The Forgotten ownCloud vulnerability (CVE-2023-49105)
ID: 5f3de87c-0bcf-5350-876d-8b5b00af2caa
STIX ID: report--5f3de87c-0bcf-5350-876d-8b5b00af2caa
Feed Name: GreyNoise Labs
Threat Score
This report analyzes CVE-2023-49105 in ownCloud, an authentication bypass where the Signed URL Verifier uses an empty per-user signing-key (default) allowing attackers to craft valid OC-Signature values and read or list arbitrary user files; the authors present code-level analysis, a proof-of-concept signing procedure with curl examples, and recommend applying the available patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
