news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2023-49105

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
9.8 Critical
Vector
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
Risk score
100.0
Known exploited
CISA KEV
Published
2023-11-21
Status
Published

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

Weaknesses

CWE-287

Coverage 1

Advisories and references