Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-49105
HistoryNov 21, 2023 - 12:00 a.m.

CVE-2023-49105

2023-11-2100:00:00
ubuntu.com
ubuntu.com
46
owncloud
vulnerability
unauthorized access

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.6 High

AI Score

Confidence

High

0.188 Low

EPSS

Percentile

96.3%

An issue was discovered in ownCloud owncloud/core before 10.13.1. An
attacker can access, modify, or delete any file without authentication if
the username of a victim is known, and the victim has no signing-key
configured. This occurs because pre-signed URLs can be accepted even when
no signing-key is configured for the owner of the files. The earliest
affected version is 10.6.0.

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.6 High

AI Score

Confidence

High

0.188 Low

EPSS

Percentile

96.3%