ownCloud ownCloud: ownCloud Improper Authentication Vulnerability
Info Listed in CISA KEV
Summary
ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- ownCloud:ownCloud
Sources
- CISA KEV DATABASE
Original Links
- https://owncloud.org/security reference
- https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ reference
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk reference
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk reference
- https://nvd.nist.gov/vuln/detail/CVE-2023-49105 reference
Timeline
- kev_ingest CISA KEV