Vulnerability Details CVE-2020-16144
When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and another user uploads a virus the files antivirus app would detect the virus but fails to delete it due to permission issues. This affects the files_antivirus component versions before 0.15.2 for ownCloud.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 40.4%
CVSS Severity
CVSS v3 Score 5.7
CVSS v2 Score 3.5
Products affected by CVE-2020-16144
-
cpe:2.3:a:owncloud:files_antivirus:0.11.2
-
cpe:2.3:a:owncloud:files_antivirus:0.12.0
-
cpe:2.3:a:owncloud:files_antivirus:0.13.0
-
cpe:2.3:a:owncloud:files_antivirus:0.14.0
-
cpe:2.3:a:owncloud:files_antivirus:0.15.0
-
cpe:2.3:a:owncloud:files_antivirus:0.15.1
-
cpe:2.3:a:owncloud:files_antivirus:0.7.0
-
cpe:2.3:a:owncloud:files_antivirus:0.7.0.1
-
cpe:2.3:a:owncloud:files_antivirus:0.7.0.2
-
cpe:2.3:a:owncloud:files_antivirus:0.8.0.1