Security
Security information
This page hosts our security policies and information with regards to reporting security flaws. You can follow our advisories via RSS.
If you are looking for information on encryption, see this blog. For more general information around security, see our FAQ questions around security and follow our development on owncloud.org/news to learn about security improvements like those introduced in ownCloud 8.1 and how others see our efforts. For server owners, our documentation has a section with best practices and tips on securing an ownCloud server.
If you've discovered a security issue with ownCloud, please read our responsible disclosure guidelines and contact us at https://hackerone.com/owncloud. Your report should include:
- Product version
- A vulnerability description
- Reproduction steps
PGP Key for Submissions
In order to facilitate secure submission of security issues, we provide the following PGP key for confidential submission:- Key ID:
61709BEF - Fingerprint:
491F D927 C0D9 E24E 8AD7 C167 DC3F 85FE 6170 9BEF - Expires:
2018-02-11
Note: Make sure to not disclose details in the subject, as it will not be encrypted!
Responsible Disclosure Guidelines
The ownCloud community kindly requests that you comply with the following guidelines when researching and reporting security vulnerabilities:- Only test for vulnerabilities on your own install of ownCloud Server
- Confirm the vulnerability applies to a supported product version
- Share vulnerabilities in detail only with the security team
- Allow reasonable time for a response from the security team
- Do not publish information related to the vulnerability until ownCloud has made an announcement to the community
Out of scope
Usually, the following types of bugs are out of scope from our security program:- User enumeration
- Network level vulnerabilities (e.g. DDoS)
Supported Product Versions
ownCloud Server:- 8.1.x
- 8.2.x
- 9.0.x
- 9.1.x
- 2.0.x
Unsupported Product Versions
ownCloud Server:- 1.x to 8.0.x (We strongly suggest to upgrade to the latest release)
- 1.0.x to 1.8.x (We strongly suggest to upgrade to the latest release)