An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 02 Apr 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Owncloud owncloud Server
CPEs cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:*
Vendors & Products Owncloud owncloud
Owncloud owncloud Server

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-29T20:42:13.587Z

Reserved: 2023-11-21T00:00:00

Link: CVE-2023-49105

cve-icon Vulnrichment

Updated: 2024-08-02T21:46:29.148Z

cve-icon NVD

Status : Analyzed

Published: 2023-11-21T22:15:08.613

Modified: 2025-04-02T14:17:25.977

Link: CVE-2023-49105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.