CVE-2015-4456
ownCloud Desktop App vulnerability analysis and mitigation

ownCloud Desktop Client before 1.8.2 does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which allows man-in-the-middle attackers to bypass the user's certificate distrust decision and obtain sensitive information by leveraging a self-signed certificate and a connection to a server using its own self-signed certificate.


SourceNVD

Related ownCloud Desktop App vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2016-7102HIGH8.4
  • ownCloud Desktop App logoownCloud Desktop App
  • cpe:2.3:a:owncloud:owncloud_desktop_client
NoYesJan 23, 2017
CVE-2021-44537HIGH7.8
  • ownCloud Desktop App logoownCloud Desktop App
  • owncloud-client
NoYesJan 15, 2022
CVE-2020-28646HIGH7.8
  • ownCloud Desktop App logoownCloud Desktop App
  • cpe:2.3:a:owncloud:owncloud_desktop_client
NoYesFeb 26, 2021
CVE-2015-7298MEDIUM5.1
  • Qt logoQt
  • owncloud-client
NoYesOct 26, 2015
CVE-2015-4456LOW2.6
  • ownCloud Desktop App logoownCloud Desktop App
  • owncloud-client
NoYesOct 26, 2015

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management