{"id":"GHSA-qm4x-ch5w-gr62","summary":"XXE in SabreDAV","details":"SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.","aliases":["CVE-2014-2055"],"modified":"2025-03-31T13:53:06.463468Z","published":"2022-05-17T04:42:42Z","database_specific":{"github_reviewed_at":"2023-07-07T19:42:46Z","nvd_published_at":"2014-06-04T14:55:00Z","cwe_ids":[],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-2055"},{"type":"WEB","url":"https://github.com/sabre-io/dav/issues/414"},{"type":"WEB","url":"https://github.com/sabre-io/dav/commit/e3f46e0ecf83cf1d2ebf54908cde7b5ec170aa2c"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/sabre/dav/CVE-2014-2055.yaml"},{"type":"WEB","url":"https://github.com/fruux/sabre-dav/releases/tag/1.7.11"}],"affected":[{"package":{"name":"sabre/dav","ecosystem":"Packagist","purl":"pkg:composer/sabre/dav"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.6.0"},{"fixed":"1.7.11"}]}],"versions":["1.6.0","1.6.1","1.6.10","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.6.7","1.6.8","1.6.9","1.7.0","1.7.1","1.7.10","1.7.2","1.7.3","1.7.4","1.7.5","1.7.6","1.7.7","1.7.8","1.7.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qm4x-ch5w-gr62/GHSA-qm4x-ch5w-gr62.json"}},{"package":{"name":"sabre/dav","ecosystem":"Packagist","purl":"pkg:composer/sabre/dav"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.8.0"},{"fixed":"1.8.9"}]}],"versions":["1.8.0","1.8.1","1.8.2","1.8.3","1.8.4","1.8.5","1.8.6","1.8.7","1.8.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qm4x-ch5w-gr62/GHSA-qm4x-ch5w-gr62.json"}}],"schema_version":"1.9.0"}