CVE-2020-36251
ownCloud Server before 10.3.0 allows an attacker, who has received non-administrative access to a group share, to remove everyone else’s access to that share.
Date published : 2021-02-19
https://owncloud.com/security-advisories/deleting-received-group-share-for-whole-group/