CVE-2014-2050: ownCloud
Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.
Affected products
- ownCloud ownCloud: before 5.0.15 (fixed in 5.0.15)
- ownCloud ownCloud Server: from 6.0.0, before 6.0.2 (fixed in 6.0.2)
Published 2020-01-23. Last modified 2026-06-17.