Loading
Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.
Use CWE-384, Owncloud vendor hub and Owncloud product page to widen CVE-2021-35948 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-35946, CVE-2020-28645 and CVE-2020-10252 for nearby disclosures in the same product family.