EXPOSURES › CVE-2023-49105
CVE-2023-49105
HIGH ⌖ ON CISA KEV · EXPLOITEDownCloud's improper authentication flaw lets attackers access, modify, or delete files without authentication if a victim's username is known and no signing key is configured.
This improper authentication vulnerability allows unauthenticated access to files, violating data integrity and confidentiality. DIBs must ensure signing keys are configured and monitor for username-based attacks. The flaw is actively exploited in the wild, indicating a high risk of data exfiltration or ransomware deployment.
Shame score — A known authentication bypass allowing unauthenticated file access is a severe, avoidable failure that directly compromises data integrity and confidentiality.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.