An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 02 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Owncloud owncloud Server
|
|
| CPEs | cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Owncloud owncloud
|
Owncloud owncloud Server
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-29T20:42:13.587Z
Reserved: 2023-11-21T00:00:00
Link: CVE-2023-49105
Updated: 2024-08-02T21:46:29.148Z
Status : Analyzed
Published: 2023-11-21T22:15:08.613
Modified: 2025-04-02T14:17:25.977
Link: CVE-2023-49105
No data.
OpenCVE Enrichment
No data.
Weaknesses