PT-2023-7303 · Owncloud · Owncloud

CVE-2023-49105

·

Published

2023-11-21

·

Updated

2026-09-04

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ownCloud versions 10.6.0 through 10.13.0
Description An authentication bypass exists in the WebDAV API implementation and the graphapi app. The issue occurs because pre-signed URLs are accepted even when no signing-key is configured for the file owner. An unauthenticated attacker who knows a victim's username can access, modify, or delete arbitrary files. This flaw was exploited by a Chinese-speaking threat actor to exfiltrate nuclear records from the Philippine Nuclear Research Institute (PNRI). The vulnerability is linked to initialization errors in the TokenAuthModule::auth() method and affects the /ocs/v2.php/apps/graphapi endpoint.
Recommendations Update ownCloud to version 10.13.1 or later. Update the graphapi app to version 0.3.1 or later. Review access logs for anomalous GET requests to the /ocs/v2.php/apps/graphapi endpoint.

Exploit

Fix

Improper Initialization

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-08331
CVE-2023-49105

Affected Products

Owncloud