CVE-2015-5955

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
29/10/2015
Last modified:
12/04/2025

Description

ownCloud iOS app before 3.4.4 does not properly switch state between multiple instances, which might allow remote instance administrators to obtain sensitive credential and cookie information by reading authentication headers.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:owncloud:owncloud_client:*:*:*:*:*:iphone_os:*:* 3.4.4 (excluding)