The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-35949.json"