云虫漏洞库

CVE-2023-49105 - An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0. - 漏洞详情

漏洞编号:CVE-2023-49105

风险等级:危急

漏洞来源:CVE

CVE 编号:CVE-2023-49105

CNNVD 编号:-

厂商/产品:owncloud / owncloud_server

影响范围:cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:*

CWE:CWE-287

发布/更新时间:2023-11-21 / 2026-08-28

漏洞描述

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

相关链接

相关漏洞

« 返回首页