CVE-2013-1941: ownCloud
Medium severity, CVSS 5.0. EPSS: 1.1% chance of exploitation in the next 30 days.
The installation routine in ownCloud Server before 4.0.14, 4.5.x before 4.5.9, and 5.0.x before 5.0.4 uses the time function to seed the generation of the PostgreSQL database user password, which makes it easier for remote attackers to guess the password via a brute force attack.
Affected products
- ownCloud ownCloud: up to and including 4.0.13
- ownCloud ownCloud Server: version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; version 4.0.5 only; …
Published 2014-06-04. Last modified 2026-06-16.