A crucial vulnerability in ownCloud servers is being exploited en masse

A crucial vulnerability in ownCloud servers is being exploited en masse - Cve 2023 49103 - Cve 2023 49104 - Cve 2023 49105 -

Last updated 13 month ago

The Web
Security
php
owncloud

A crucial vulnerability in ownCloud servers is being exploited en masse



Facepalm: OwnCloud is an open-source software program designed for sharing and syncing files in allotted and federated business enterprise environments. The tool provides collaboration and file-sharing services, however a lately disclosed vulnerability has extended its "sharing" talents in an unintentional way, compromising sensitive information.

This beyond week, ownCloud publicly disclosed a essential vulnerability inside the "graphapi" app. The security flaw is being tracked with the very best stage of risk on the CVE scale (10) as CVE-2023-49103. A week later, protection researchers have now started out to witness what should quantity to "mass" exploitation of this extremely dangerous flaw.

According to ownCloud's respectable advisory, the CVE-2023-49103 difficulty stems from a 3rd-celebration library used by the graphapi app (GetPhpInfo.Personal home page). The library offers a URL that, when accessed, well-knownshows the configuration details of the PHP surroundings. The supplied facts also consists of all the environment variables of the webserver, ownCloud said.

The problem basically arises in containerized deployments of ownCloud, in which the environment variables disclosed by means of getphpinfo.Php "may encompass" touchy information including admin passwords, server credentials, and license keys. Simply disabling the graphapi app would not get rid of the vulnerability, because the flawed library nevertheless affords the secret-disclosing URL, according to ownCloud.

Aside from disclosing server secrets, the prone phpinfo library can disclose different doubtlessly sensitive configuration details that an attacker may want to make the most to accumulate similarly facts approximately the system. Even if ownCloud isn't always jogging in a containerized environment, the advisory warns, server admins should nonetheless be concerned approximately the vulnerability's potential consequences.

According to security organisation GreyNoise, the CVE-2023-49103 flaw is now actively being exploited by cyber-criminals. Researchers describe a "mass exploitation" of the flaw within the wild, which they detected as early as November 25, 2023. Black hat hackers are seeking passwords, mail server credentials, and license keys, which the distinctive vulnerability might gladly display to every body.

While the organisation is working on "diverse hardenings" in destiny middle releases to avoid comparable vulnerabilities, ownCloud cautioned customers to delete the wrong GetPhpInfo.Hypertext Preprocessor library from their servers. Furthermore, the phpinfo feature turned into disabled in the bins the German agency immediately offers to its corporation customers.

Further advice provided via ownCloud includes a global reset of server "secrets," which include passwords, credentials, and get entry to keys. In addition to CVE-2023-49103, GreyNoise feedback that ownCloud these days disclosed additional vital vulnerabilities. The flaws consist of an authentication bypass trouble with a 9.8 CVE score (CVE-2023-49105) and a relatively risky flaw related to the oauth2 app (CVE-2023-49104).

  • Cve 2023 49103

  • Cve 2023 49104

  • Cve 2023 49105

  • Cve 2023 49103 nextcloud

IPhone income tumble in China: a 30% lower adds to Apple's difficult instances

IPhone income tumble in China: a 30% lower adds to Apple's difficult instances

 Apple is probably the biggest business enterprise inside the international through marketplace cap, however no longer the entirety is going Cupertino's manner. The tech massive has had a hard few weeks, and it seems li...

Last updated 12 month ago

Logitech launches a $299 racing cockpit that doubles as a folding chair

Logitech launches a $299 racing cockpit that doubles as a folding chair

What just came about? Logitech has added a cockpit designed for racing simulators that also serves as a folding chair. Named the Playseat Challenge X – Logitech G Edition, this tool became advanced by Logitech G in coll...

Last updated 16 month ago

Frore Systems unveils a thinner, lighter, and smarter model of its AirJet Mini fanless cooler

Frore Systems unveils a thinner, lighter, and smarter model of its AirJet Mini fanless cooler

In a nutshell: Frore Systems has hit the Las Vegas strip with a thinner and lighter version of its AirJet Mini cooling system. The newly minted AirJet Mini Slim builds at the success of the unique, which earned a Golden...

Last updated 12 month ago

Dutch organisation well-knownshows plans for 90-passenger electric aircraft capable of tour 500 miles

Dutch organisation well-knownshows plans for 90-passenger electric aircraft capable of tour 500 miles

Forward-searching: A Dutch corporation has announced plans to develop an electric aircraft able to sporting ninety passengers. The business enterprise notes in newly published studies papers that "big battery-elect...

Last updated 12 month ago

The Best Gaming Laptops 2023: Gaming at the Go

The Best Gaming Laptops 2023: Gaming at the Go

For selecting the quality gaming laptops, we have split our recommendations into awesome classes based on use case, price range, and form thing, masking the excellent finances laptops you could nonetheless game on, to a...

Last updated 14 month ago

Family sues Google after man dies riding off collapsed bridge following Maps directions

Family sues Google after man dies riding off collapsed bridge following Maps directions

 Google is being sued by way of the circle of relatives of a North Carolina man who drove his vehicle off a collapsed bridge as he observed guidelines given by Google Maps. It's claimed that Google acted negligently, be...

Last updated 16 month ago


safirsoft.com© 2023 All rights reserved

HOME | TERMS & CONDITIONS | PRIVACY POLICY | Contact