CVE-2014-2050: ownCloud

Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.

Affected products

  • ownCloud ownCloud: before 5.0.15 (fixed in 5.0.15)
  • ownCloud ownCloud Server: from 6.0.0, before 6.0.2 (fixed in 6.0.2)

Published 2020-01-23. Last modified 2026-06-17.