Description
The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused to spoof the URL in password-reset e-mail messages.
Remediation
References
Related Vulnerabilities
Oracle Application Server CVE-2008-4014 Vulnerability (CVE-2008-4014)
WordPress Plugin mySTAT 'mystat.php' SQL Injection (2.6)
MediaWiki Use of Hard-coded Credentials Vulnerability (CVE-2012-4381)
WordPress Plugin Markup (JSON-LD) structured in schema.org Cross-Site Scripting (4.8.1)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-14885)