Description
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 27 Feb 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Owncloud owncloud Server
|
|
| CPEs | cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Owncloud owncloud
|
Owncloud owncloud Server
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-29T20:42:13.587Z
Reserved: 2023-11-21T00:00:00.000Z
Link: CVE-2023-49105
Updated: 2024-08-02T21:46:29.148Z
Status : Analyzed
Published: 2023-11-21T22:15:08.613
Modified: 2025-04-02T14:17:25.977
Link: CVE-2023-49105
No data.
OpenCVE Enrichment
No data.
Weaknesses