PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5865 Owncloud CVE debrief

CVE-2017-5865 is an information-disclosure issue in ownCloud Server's password-reset flow. In affected versions, the application returned different error messages depending on whether a username was valid, which let remote attackers enumerate user names by repeatedly attempting password resets. The fix is to move to a patched release and ensure the reset flow does not reveal account existence through its responses.

Vendor
Owncloud
Product
Unknown
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2017-03-03
Original CVE updated
2026-05-13
Advisory published
2017-03-03
Advisory updated
2026-05-13

Who should care

ownCloud administrators, identity and authentication owners, and security teams running affected Server versions before 8.1.11, 8.2.9, 9.0.7, or 9.1.3.

Technical summary

The supplied NVD data maps this issue to CWE-200 and CVSS 3.0 AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. The vulnerable behavior is limited to the password-reset endpoint: response differences disclose whether a submitted username exists. That supports account enumeration over the network, but the record does not indicate direct code execution, privilege gain, or service disruption.

Defensive priority

Low for immediate impact, but worth addressing promptly if the instance is internet-facing or if account discovery would materially help follow-on attacks.

Recommended defensive actions

  • Upgrade ownCloud Server to 8.1.11, 8.2.9, 9.0.7, 9.1.3, or later.
  • Verify the password-reset flow returns consistent responses that do not confirm whether a username exists.
  • Add rate limiting and alerting around repeated password-reset requests.
  • Review exposure of authentication endpoints and restrict access where practical.
  • Use the vendor advisory to confirm remediation steps for your deployed version.

Evidence notes

The supplied corpus states that ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages during password reset, enabling remote username enumeration. NVD classifies the weakness as CWE-200 and provides CVSS 3.0 AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. The CVE was published on 2017-03-03; the 2026-05-13 modified timestamp is record metadata and should not be treated as the original disclosure date.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5865 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5865

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5865 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5865

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.