logo

Details and Caveats for ownCloud information disclosure (CVE-2023-49103)

ID: 00952984-d670-5e94-9b20-a6be5fb6b9ce

STIX ID: report--00952984-d670-5e94-9b20-a6be5fb6b9ce

Feed Name: GreyNoise Labs

Threat Score
30/100

Date Published: 2023-11-29

Date Updated: 2026-04-27

Author: Ron Bowes

...
...

This report analyzes CVE-2023-49103 (ownCloud Graph API information disclosure) showing how a test file calling phpinfo() can leak environment variables (including credentials) under certain configurations; it documents testing with Docker, how an htaccess RewriteRule/mod_rewrite behavior commonly prevents the exploit, conditions that make instances vulnerable (htaccess.RewriteBase unset or misconfigured), evidence of scanning in the wild, and recommends patching and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.