CVE-2014-5341: ownCloud

Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.

The SFTP external storage driver (files_external) in ownCloud Server before 6.0.5 validates the RSA Host key after login, which allows remote attackers to obtain sensitive information by sniffing the network.

Affected products

  • ownCloud ownCloud: up to and including 6.0.4

Published 2015-02-04. Last modified 2026-06-17.