CVE-2014-2049: ownCloud

Medium severity, CVSS 5.0. EPSS: 1.3% chance of exploitation in the next 30 days.

The default Flash Cross Domain policies in ownCloud before 5.0.15 and 6.x before 6.0.2 allows remote attackers to access user files via unspecified vectors.

Affected products

  • ownCloud ownCloud: up to and including 5.0.14
  • ownCloud ownCloud Server: version 6.0.0 only; version 6.0.1 only; version 3.0.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; …

Published 2014-03-14. Last modified 2026-06-17.