• Latest
  • Trending
  • All
ownCloud vulnerability with maximum 10 severity score comes under “mass” exploitation

ownCloud vulnerability with maximum 10 severity score comes under “mass” exploitation

3 years ago
Indian-Origin American Citizens Among 17 Individuals To Be Deneutralised By US In Rare Move

Indian-Origin American Citizens Among 17 Individuals To Be Deneutralised By US In Rare Move

2 hours ago
Government Reduces Annual Subsidised LPG Cylinder Quota For Ujjwala Beneficiaries To Four | India News

Government Reduces Annual Subsidised LPG Cylinder Quota For Ujjwala Beneficiaries To Four | India News

3 hours ago
Bangladesh vs Australia 1st ODI Live Streaming: When, where and how to watch BAN vs AUS live on TV and online

Bangladesh vs Australia 1st ODI Live Streaming: When, where and how to watch BAN vs AUS live on TV and online

3 hours ago
Refrigerator Buying Guide 2026: Single Door, Double Door & Inverter Tech | Tech News

Refrigerator Buying Guide 2026: Single Door, Double Door & Inverter Tech | Tech News

3 hours ago
India’s anti-obesity drug market sees slower growth after initial surge in generic semaglutide sales

India’s anti-obesity drug market sees slower growth after initial surge in generic semaglutide sales

5 hours ago
Tata Trusts board meets ahead of key Tata Sons board meeting | Business News

Tata Trusts board meets ahead of key Tata Sons board meeting | Business News

8 hours ago
TMC rebel MPs hold meeting at Union Minister’s Bhupender Yadav residence

TMC rebel MPs hold meeting at Union Minister’s Bhupender Yadav residence

10 hours ago
Apple WWDC 2026 LIVE | iPhone-maker announces Siri AI powered by the new Apple Intelligence

Apple WWDC 2026 LIVE | iPhone-maker announces Siri AI powered by the new Apple Intelligence

11 hours ago
Ben Stokes, Gus Atkinson under ECB investigation after nightclub incident; Oval Test spots under cloud

Ben Stokes, Gus Atkinson under ECB investigation after nightclub incident; Oval Test spots under cloud

11 hours ago
India’s Q4 FY26 Current Account Surplus Driven by Services Exports, Remittances

India’s Q4 FY26 Current Account Surplus Driven by Services Exports, Remittances

12 hours ago
Women’s T20 WC: India pin faith on the Shafali-Smriti opening salvo

Women’s T20 WC: India pin faith on the Shafali-Smriti opening salvo

13 hours ago
PIO Nithya Raman surges into LA Mayoral runoff spot, triggering Trump fury over another ‘stolen’ election

PIO Nithya Raman surges into LA Mayoral runoff spot, triggering Trump fury over another ‘stolen’ election

14 hours ago
Tuesday, June 9, 2026
  • PRESS RELEASE
  • ADVERTISE
  • CONTACT
  • Game
India News Online
  • Home
  • News
    • India
    • Punjab
    • International
    • Entertainment
  • Hindi News
  • Politics
  • Health
  • Business
  • Sports
  • Technology
  • Lifestyle
  • Video
    • All
    • Hindi Songs
    • Punjabi Songs
    पियवा किसनवा 90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu songs Hindi

    पियवा किसनवा 90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu songs Hindi

    90s Bollywood Wedding Songs | Evergreen Bollywood Hits | Shadi Song | Sadabahar Hindi Songs Jukebox

    90s Bollywood Wedding Songs | Evergreen Bollywood Hits | Shadi Song | Sadabahar Hindi Songs Jukebox

    आज तो बाल बाल बच गया😄90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu song

    आज तो बाल बाल बच गया😄90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu song

    भाभी ने बचाई ननद की जान 😆 90’S Old Hindi Songs 🥺90s Love Song 😍Udit Narayan, Alka Yagnik, Kumar

    भाभी ने बचाई ननद की जान 😆 90’S Old Hindi Songs 🥺90s Love Song 😍Udit Narayan, Alka Yagnik, Kumar

    When Online Love Becomes Real💞Chinese mix Hindi Songs💞Cin Klip💞Chinese Drama💞Korean Mix Hindi Songs

    When Online Love Becomes Real💞Chinese mix Hindi Songs💞Cin Klip💞Chinese Drama💞Korean Mix Hindi Songs

    Cold Rude boy falling for cute girl 💕 korean mix hindi songs 💞 Chinese mix hindi songs

    Cold Rude boy falling for cute girl 💕 korean mix hindi songs 💞 Chinese mix hindi songs

    90s हिंदी सदाबहार गीत | 90’s Romantic Hindi Songs | 90’s सदाबहार फिल्मी गाने | 90’s Bollywood Songs

    90s हिंदी सदाबहार गीत | 90’s Romantic Hindi Songs | 90’s सदाबहार फिल्मी गाने | 90’s Bollywood Songs

    90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu songs Hindi Jukebox

    90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu songs Hindi Jukebox

    90’s हिंदी गाने | 90’s Evergreen Songs | 90s सदाबहार गाने | Hindi Gana | 90’s Hit Songs | Durga Boss

    90’s हिंदी गाने | 90’s Evergreen Songs | 90s सदाबहार गाने | Hindi Gana | 90’s Hit Songs | Durga Boss

  • Travel
  • Game
No Result
View All Result
India News
No Result
View All Result
Home Technology

ownCloud vulnerability with maximum 10 severity score comes under “mass” exploitation

by India News Online Team
November 29, 2023
in Technology
0
ownCloud vulnerability with maximum 10 severity score comes under “mass” exploitation
Share on FacebookShare on TwitterShare on Email


ownCloud vulnerability with maximum 10 severity score comes under “mass” exploitation

Getty Images

Security researchers are tracking what they say is the “mass exploitation” of a security vulnerability that makes it possible to take full control of servers running ownCloud, a widely used open-source filesharing server app.

The vulnerability, which carries the maximum severity rating of 10, makes it possible to obtain passwords and cryptographic keys allowing administrative control of a vulnerable server by sending a simple Web request to a static URL, ownCloud officials warned last week. Within four days of the November 21 disclosure, researchers at security firm Greynoise said, they began observing “mass exploitation” in their honeypot servers, which masqueraded as vulnerable ownCloud servers to track attempts to exploit the vulnerability. The number of IP addresses sending the web requests has slowly risen since then. At the time this post went live on Ars, it had reached 13.

Spraying the Internet

“We’re seeing hits to the specific endpoint that exposes sensitive information, which would be considered exploitation,” Glenn Thorpe, senior director of security research & detection engineering at Greynoise, said in an interview on Mastodon. “At the moment, we’ve seen 13 IPs that are hitting our unadvertised sensors, which indicates that they are pretty much spraying it across the internet to see what hits.”

CVE-2023-49103 resides in versions 0.2.0 and 0.3.0 of graphapi, an app that runs in some ownCloud deployments, depending on the way they’re configured. A third-party code library used by the app provides a URL that, when accessed, reveals configuration details from the PHP-based environment. In last week’s disclosure, ownCloud officials said that in containerized configurations—such as those using the Docker virtualization tool—the URL can reveal data used to log into the vulnerable server. The officials went on to warn that simply disabling the app in such cases wasn’t sufficient to lock down a vulnerable server.

Advertisement

The ownCloud advisory explained:

The “graphapi” app relies on a third-party library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key.

It’s important to emphasize that simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system. Therefore, even if ownCloud is not running in a containerized environment, this vulnerability should still be a cause for concern.

Not all security practitioners regard the vulnerability as posing a widespread threat, the way other vulnerabilities—most recently the vulnerability tracked as CVE-2023-4966 and CitrixBleed—have. Specifically, independent researcher Kevin Beaumont has noted that the CVE-2023-49103 vulnerability wasn’t introduced until 2020, isn’t exploitable by default, and was only introduced in containers in February.

“I don’t think anybody else actually checked if the vulnerable feature is enabled,” he said in an interview. What’s more, an ownCloud Web page showed graphapi had fewer than 900 installs at the time this post went live on Ars. ownCloud officials didn’t immediately respond to an email seeking technical details of the vulnerability and the precise conditions required for it to be exploited.

Given the potential threat posed by CVE-2023-49103, there’s still room for legitimate concern. According to security organization Shadowserver, a recent scan revealed more than 11,000 IP addresses hosting ownCloud servers, led by addresses in Germany, the US, France, Russia, and Poland. Even if only a small fraction of the servers are vulnerable, the potential for harm is real.

Advertisement

“Not surprisingly given ease of exploitation we have started seeing OwnCloud CVE-2023-49103 attempts,” Shadowserver officials wrote. “This is a CVSS 10 disclosure of sensitive credentials & configs in containerized deployments. Please follow ownCloud advisory mitigation steps.”

More high-severity ownCloud vulnerabilities

Another reason for concern: ownCloud recently fixed two other high-severity vulnerabilities, including CVE-2023-94105, which has a severity rating of 9.8. The flaw allows for an authentication bypass in the WebDAV API using pre-signed URLs. Hackers can exploit it “to access, modify or delete any file without authentication if the username of the victim is known and the victim has no signing-key configured (which is the default),” ownCloud officials warned. The vulnerability affects the WebDAV API in ownCloud versions 10.6.0 to 10.13.0.

A third vulnerability tracked as CVE-2023-94104 is a subdomain validation bypass flaw with a severity rating of 8.7. Hackers can exploit it using a redirect URL, making it possible to redirect callbacks to a domain controlled by the attacker.

To fix the ownCloud vulnerability under exploitation, ownCloud advised users to:

Delete the file owncloud/apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php. Additionally, we disabled the phpinfo function in our docker-containers. We will apply various hardenings in future core releases to mitigate similar vulnerabilities.

We also advise to change the following secrets:
– ownCloud admin password
– Mail server credentials
– Database credentials
– Object-Store/S3 access-key

While there are no reports of the other two vulnerabilities being actively exploited, users should follow the instructions ownCloud has provided here and here.

In recent months, vulnerabilities in file sharing apps such as WS-FTP server, MOVEit, and IBM Aspera Faspex, and GoAnywhere MFT have enabled the compromise of thousands of enterprise networks. Anyone who ignores the threat posed by the recently fixed ownCloud flaws does so at their own peril.



Source link

Tags: exploitationmassmaximumownCloudScoreseverityVulnerability
Share199Tweet125Send

Related Posts

Refrigerator Buying Guide 2026: Single Door, Double Door & Inverter Tech | Tech News
Technology

Refrigerator Buying Guide 2026: Single Door, Double Door & Inverter Tech | Tech News

June 9, 2026
WhatsApp Says Spyware Maker NSO Group Is Still Targeting Its Users
Technology

WhatsApp Says Spyware Maker NSO Group Is Still Targeting Its Users

June 8, 2026
Notion restores access to Anthropic after service disruption
Technology

Notion restores access to Anthropic after service disruption

June 7, 2026
School shooting survivor sues AI gun detection firm after system failed to spot weapon
Technology

School shooting survivor sues AI gun detection firm after system failed to spot weapon

June 7, 2026
Load More
  • Trending
  • Comments
  • Latest
9 Festivals to Celebratein August in India

9 Festivals to Celebratein August in India

August 8, 2025
Corruption cases against govt officials: SC bats for striking balance | Latest News India

Corruption cases against govt officials: SC bats for striking balance | Latest News India

August 5, 2025
Guru Randhawa – SIRRA ( Official Video )

Guru Randhawa – SIRRA ( Official Video )

July 1, 2025
Baharon Phool Barsao – Suraj – Rajendra Kumar, Vyjayanthimala – Old Hindi Songs

Baharon Phool Barsao – Suraj – Rajendra Kumar, Vyjayanthimala – Old Hindi Songs

0
Phool Maangu Na Bahaar Maangu – Video Song | Raja | Madhuri Dixit & Sanjay Kapoor

Phool Maangu Na Bahaar Maangu – Video Song | Raja | Madhuri Dixit & Sanjay Kapoor

0
Dil Ka Rishta Song – Aishwarya Rai,Arjun Rampal, Alka Yagnik,Udit Narayan,Kumar Sanu, Nadeem-Shravan

Dil Ka Rishta Song – Aishwarya Rai,Arjun Rampal, Alka Yagnik,Udit Narayan,Kumar Sanu, Nadeem-Shravan

0
Indian-Origin American Citizens Among 17 Individuals To Be Deneutralised By US In Rare Move

Indian-Origin American Citizens Among 17 Individuals To Be Deneutralised By US In Rare Move

June 9, 2026
Government Reduces Annual Subsidised LPG Cylinder Quota For Ujjwala Beneficiaries To Four | India News

Government Reduces Annual Subsidised LPG Cylinder Quota For Ujjwala Beneficiaries To Four | India News

June 9, 2026
Bangladesh vs Australia 1st ODI Live Streaming: When, where and how to watch BAN vs AUS live on TV and online

Bangladesh vs Australia 1st ODI Live Streaming: When, where and how to watch BAN vs AUS live on TV and online

June 9, 2026
India News Online

24x7 Online News From India
India News Online is your news, entertainment, music fashion website. We provide you with the latest breaking news and videos straight from the entertainment industry.

Categories

  • Business
  • Entertainment
  • Health
  • Hindi News
  • Hindi Songs
  • India
  • International
  • Lifestyle
  • Panjab
  • Politics
  • Punjabi Songs
  • Sports
  • Technology
  • Travel
  • Uncategorized
No Result
View All Result

Recent Posts

  • Indian-Origin American Citizens Among 17 Individuals To Be Deneutralised By US In Rare Move
  • Government Reduces Annual Subsidised LPG Cylinder Quota For Ujjwala Beneficiaries To Four | India News
  • Bangladesh vs Australia 1st ODI Live Streaming: When, where and how to watch BAN vs AUS live on TV and online
  • Home
  • Disclaimer
  • DMCA
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact

Copyright © 2021 - India News Online.

No Result
View All Result
  • Home
  • News
    • India
    • Punjab
    • International
    • Entertainment
  • Hindi News
  • Politics
  • Health
  • Business
  • Sports
  • Technology
  • Lifestyle
  • Video
  • Travel
  • Game

Copyright © 2021 - India News Online.