CVE-2014-2048: ownCloud

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation.

Affected products

  • ownCloud ownCloud: before 5.0.15 (fixed in 5.0.15)

Published 2018-03-26. Last modified 2026-06-17.