{"id":"CVE-2021-29659","details":"ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in the related API endpoint, the attacker can enumerate all users in a single request by entering three whitespaces. Secondary, the retrieval of all users on a large instance could cause higher than average load on the instance.","modified":"2026-07-09T00:13:55.909485Z","published":"2021-05-20T13:15:07.627Z","references":[{"type":"ADVISORY","url":"https://doc.owncloud.com/server/admin_manual/release_notes.html"},{"type":"ADVISORY","url":"https://owncloud.com/security-advisories/cve-2021-29659/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/owncloud/core","events":[{"introduced":"119742ed5f9c01fd8fdae86457fd573533063a83"},{"last_affected":"119742ed5f9c01fd8fdae86457fd573533063a83"}],"database_specific":{"cpe":"cpe:2.3:a:owncloud:owncloud_server:10.7.0:-:*:*:*:*:*:*","extracted_events":[{"introduced":"10.7.0-NA"},{"last_affected":"10.7.0-NA"}],"source":"CPE_STRING"}}],"versions":["10.7.0-NA","v10.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-29659.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}