logo

The Forgotten ownCloud vulnerability (CVE-2023-49105)

ID: 5f3de87c-0bcf-5350-876d-8b5b00af2caa

STIX ID: report--5f3de87c-0bcf-5350-876d-8b5b00af2caa

Feed Name: GreyNoise Labs

Threat Score
85/100

Date Published: 2023-12-05

Date Updated: 2026-04-27

Author: Ron Bowes

...
...

This report analyzes CVE-2023-49105 in ownCloud, an authentication bypass where the Signed URL Verifier uses an empty per-user signing-key (default) allowing attackers to craft valid OC-Signature values and read or list arbitrary user files; the authors present code-level analysis, a proof-of-concept signing procedure with curl examples, and recommend applying the available patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.