The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection.
📦
files_antivirus
Vendor: owncloud
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
2
Remote Access
Total CVEs
3
Total Indexed
Avg. EPSS
0.63%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
8.8
CVSS
CVE-2021-33828
RCE
Severity: HIGH
7.2
CVSS
CVE-2021-33827
RCE
The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.
Severity: HIGH
5.7
CVSS
When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and another user uploads a virus the files antivirus app would detect the virus but fails to delete it due to permission issues. This affects the files_antivirus component versions before 0.15.2 for ownCloud.
Severity: MEDIUM