Record summary

CVE-2023-49105 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 28, 2023 · Source: CVE List

Proofs of concept

1

Repository PoCs

GitHubambionics/owncloud-exploitsRepository PoCby ambionicsStars: 39Not analyzed2 files

3.7 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALOwnCloud - WebDAV API Authentication BypassCVSS 9.8

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

Impact

Attackers can access, modify, or delete any files without authentication, leading to data breach and integrity issues.

Remediation

Upgrade OwnCloud to version 10.13.1 or later that properly validates signing keys and authentication in the WebDAV API.

WeaknessesCWE-287
AuthorsChristianPoeschl, FlorianDewald, usdAG
Template tagscvecve2023codeowncloudauth-bypassvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:*:*:*
Shodan: title:"owncloud"
Shodan: http.title:"owncloud"
FOFA: title="owncloud"
Google: intitle:"owncloud"

Source: ProjectDiscovery

References

3