Description
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
CVSS breakdown
CVSS 3.1
Attack Complexity
Low
Attack Vector
Network
Availability
High
Confidentiality
High
Integrity
High
Privileges Required
None
Scope
Unchanged
User Interaction
None
Exploits & proofs of concept
- nucleiOwnCloud - WebDAV API Authentication Bypassby ChristianPoeschl,FlorianDewald,usdAG
Updated 24m ago · 8 sources