PT-2023-7303 · Owncloud · Owncloud
CVE-2023-49105
·
Published
2023-11-21
·
Updated
2026-09-04
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ownCloud versions 10.6.0 through 10.13.0
Description
An authentication bypass exists in the WebDAV API implementation and the
graphapi app. The issue occurs because pre-signed URLs are accepted even when no signing-key is configured for the file owner. An unauthenticated attacker who knows a victim's username can access, modify, or delete arbitrary files. This flaw was exploited by a Chinese-speaking threat actor to exfiltrate nuclear records from the Philippine Nuclear Research Institute (PNRI). The vulnerability is linked to initialization errors in the TokenAuthModule::auth() method and affects the /ocs/v2.php/apps/graphapi endpoint.Recommendations
Update ownCloud to version 10.13.1 or later.
Update the
graphapi app to version 0.3.1 or later.
Review access logs for anomalous GET requests to the /ocs/v2.php/apps/graphapi endpoint.Exploit
Fix
Improper Initialization
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Owncloud