• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
warning: 3 critical vulnerabilities expose owncloud users to data breaches

Warning: 3 Critical Vulnerabilities Expose ownCloud Users to Data Breaches

You are here: Home / General Cyber Security News / Warning: 3 Critical Vulnerabilities Expose ownCloud Users to Data Breaches
November 25, 2023

The maintainers of the open-source file-sharing software ownCloud have warned of a few critical security flaws that could be exploited to disclose delicate facts and modify information.

A quick description of the vulnerabilities is as follows –

  • Disclosure of delicate credentials and configuration in containerized deployments impacting graphapi versions from .2. to .3.. (CVSS rating: 10.)
  • WebDAV Api Authentication Bypass using Pre-Signed URLs impacting core versions from 10.6. to 10.13. (CVSS score: 9.8)
  • Subdomain Validation Bypass impacting oauth2 prior to version .6.1 (CVSS score: 9.)

“The ‘graphapi’ app depends on a third-party library that presents a URL. When this URL is accessed, it reveals the configuration details of the PHP setting (phpinfo),” the firm claimed of the 1st flaw.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

“This information contains all the surroundings variables of the web server. In containerized deployments, these surroundings variables might involve sensitive knowledge these types of as the ownCloud admin password, mail server credentials, and license key.”

As a repair, ownCloud is recommending to delete the “owncloud/applications/graphapi/vendor/microsoft/microsoft-graph/assessments/GetPhpInfo.php” file and disable the ‘phpinfo’ perform. It is also advising people to transform secrets like the ownCloud admin password, mail server and databases credentials, and Object-Retail outlet/S3 access keys.

The second challenge can make it possible to accessibility, modify or delete any file sans authentication if the username of the target is recognised and the sufferer has no signing-essential configured, which is the default behavior.

And lastly, the 3rd flaw relates to a situation of inappropriate obtain handle that allows an attacker to “pass in a specially crafted redirect-url which bypasses the validation code and hence lets the attacker to redirect callbacks to a TLD managed by the attacker.”

In addition to adding hardening actions to the validation code in the oauth2 app, ownCloud has proposed that customers disable the “Permit Subdomains” selection as a workaround.

Cybersecurity

The disclosure arrives as a proof-of-concept (PoC) exploit has been unveiled for a critical distant code execution vulnerability in the CrushFTP answer (CVE-2023-43177) that could be weaponized by an unauthenticated attacker to access documents, run arbitrary packages on the host, and receive basic-textual content passwords.

The issue has been tackled in CrushFTP model 10.5.2, which was produced on August 10, 2023.

“This vulnerability is critical because it does NOT need any authentication,” CrushFTP noted in an advisory unveiled at the time. “It can be completed anonymously and steal the session of other consumers and escalate to an administrator person.”

Located this posting exciting? Comply with us on Twitter  and LinkedIn to study a lot more exceptional content we submit.


Some parts of this short article are sourced from:
thehackernews.com

Previous Post: «cybercriminals using telekopye telegram bot to craft phishing scams on Cybercriminals Using Telekopye Telegram Bot to Craft Phishing Scams on a Grand Scale
Next Post: New ‘HrServ.dll’ Web Shell Detected in APT Attack Targeting Afghan Government new 'hrserv.dll' web shell detected in apt attack targeting afghan»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.