ownCloud Desktop Client before 1.8.2 does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which allows man-in-the-middle attackers to bypass the user's certificate distrust decision and obtain sensitive information by leveraging a self-signed certificate and a connection to a server using its own self-signed certificate.
2015-10-26T14:59:00.107
2025-04-12T10:46:40.837
Deferred
CVSSv2: 2.6 (LOW)
AV:N/AC:H/Au:N/C:P/I:N/A:N
4.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | owncloud | owncloud_desktop_client | ≤ 1.8.1 | Yes |