CVE-2023-49103
ownCloud graphapi Information Disclosure Vulnerabi - [Actively Exploited]
Description
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system. Therefore, even if ownCloud is not running in a containerized environment, this vulnerability should still be a cause for concern. Note that Docker containers from before February 2023 are not vulnerable to the credential disclosure.
INFO
Published Date :
Nov. 21, 2023, 10:15 p.m.
Last Modified :
Dec. 20, 2024, 5:26 p.m.
Source :
[email protected]
Remotely Exploitable :
Yes !
Impact Score :
6.0
Exploitability Score :
3.9
CISA KEV (Known Exploited Vulnerabilities)
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.
ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-49103
Public PoC/Exploit Available at Github
CVE-2023-49103 has a 9 public PoC/Exploit
available at Github.
Go to the Public Exploits
tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2023-49103
.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
This is a simple proof of concept for CVE-2023-49103.
Python
A curated list of CVEs, respective PoC and a docker/vm to test it.
Python Dockerfile HTML CSS
A curated list of all the CVEs, the respective PoC if found and a docker/vm to test it.
Python Dockerfile HTML CSS
OwnCloud CVE-2023-49103
Dockerfile HTML CSS
ownCloud exploits for CVE-2023-49105
Python
CVE-2023-49103 scanner for shodan.io downloaded json files
Python
PoC for the CVE-2023-49103
Python
Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.
cisa-kev vulnerability 0day cisa exploits
An evolving how-to guide for securing a Linux server.
linux hardening hardening-steps security security-hardening server linux-server cc-by-sa
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2023-49103
vulnerability anywhere in the article.
- TheCyberThrone
Top 15 Most Exploited Vulnerabilities in 2023
In a joint cybersecurity advisory, the security agencies across the world have identified the most exploited vulnerabilities of 2023. This advisory, coauthored by the Cybersecurity and Infrastructure ... Read more
- The Register
Five Eyes infosec agencies list 2024's most exploited software flaws
The cyber security agencies of the UK, US, Canada, Australia, and New Zealand have issued their annual list of the 15 most exploited vulnerabilities, and warned that attacks on zero-day exploits have ... Read more
- Cybersecurity News
2023’s Most Exploited Vulnerabilities: A Global Cybersecurity Advisory
In a joint cybersecurity advisory, the top cybersecurity agencies from the United States, Australia, Canada, New Zealand, and the United Kingdom have identified the most exploited vulnerabilities of 2 ... Read more
- The Cyber Express
Top 15 Exploited Cyber Vulnerabilities Revealed: Five Eyes Alliance Urges Immediate Patching
The FBI, NSA, and allied agencies within the Five Eyes intelligence network have published a list of the 15 most exploited vulnerabilities from 2023. The cybersecurity advisory, a collaborative effort ... Read more
- BleepingComputer
FBI, CISA, and NSA reveal most exploited vulnerabilities of 2023
The FBI, the NSA, and cybersecurity authorities of the Five Eyes intelligence alliance have released today a list of the top 15 routinely exploited vulnerabilities throughout last year. A joint advis ... Read more
- security.nl
VS publiceert overzicht van meest misbruikte kwetsbaarheden in 2023
De Amerikaanse autoriteiten hebben samen met cyberagentschappen uit Australië, Canada, Nieuw-Zeeland en het Verenigd Koninkrijk een overzicht van de meest misbruikte kwetsbaarheden in 2023 opgesteld. ... Read more
The following table lists the changes that have been made to the
CVE-2023-49103
vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Modified Analysis by [email protected]
Dec. 20, 2024
Action Type Old Value New Value -
CVE Modified by af854a3a-2127-422b-91ae-364da2661108
Nov. 21, 2024
Action Type Old Value New Value Added Reference https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ Added Reference https://owncloud.org/security -
Modified Analysis by [email protected]
Sep. 05, 2024
Action Type Old Value New Value -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Sep. 04, 2024
Action Type Old Value New Value Added CWE CISA-ADP CWE-200 -
Modified Analysis by [email protected]
Jun. 26, 2024
Action Type Old Value New Value Changed Reference Type https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ No Types Assigned https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ Vendor Advisory Changed Reference Type https://owncloud.org/security No Types Assigned https://owncloud.org/security Product -
CVE Modified by [email protected]
May. 14, 2024
Action Type Old Value New Value -
CVE Modified by [email protected]
Dec. 05, 2023
Action Type Old Value New Value Added Reference MITRE https://owncloud.org/security [No types assigned] Added Reference MITRE https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ [No types assigned] Removed Reference Microsoft Corporation https://owncloud.org/security Removed Reference Microsoft Corporation https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ Removed CVSS V3.1 Microsoft Corporation AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Added CVSS V3.1 MITRE AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H -
CVE Source Update by [email protected]
Dec. 05, 2023
Action Type Old Value New Value Changed Source Microsoft Corporation MITRE -
CVE Modified by [email protected]
Dec. 05, 2023
Action Type Old Value New Value Added Reference Microsoft Corporation https://owncloud.org/security [No types assigned] Added Reference Microsoft Corporation https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ [No types assigned] Removed Reference MITRE https://owncloud.org/security Removed Reference MITRE https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ Removed CVSS V3.1 MITRE AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Added CVSS V3.1 Microsoft Corporation AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H -
CVE Source Update by [email protected]
Dec. 05, 2023
Action Type Old Value New Value Changed Source MITRE Microsoft Corporation -
Initial Analysis by [email protected]
Dec. 02, 2023
Action Type Old Value New Value Added CVSS V3.1 NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Changed Reference Type https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ No Types Assigned https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ Mitigation, Vendor Advisory Changed Reference Type https://owncloud.org/security No Types Assigned https://owncloud.org/security Product Added CWE NIST NVD-CWE-noinfo Added CPE Configuration OR *cpe:2.3:a:owncloud:graph_api:0.2.0:*:*:*:*:*:*:* *cpe:2.3:a:owncloud:graph_api:0.3.0:*:*:*:*:*:*:* -
CVE Received by [email protected]
Nov. 21, 2023
Action Type Old Value New Value Added Description An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system. Therefore, even if ownCloud is not running in a containerized environment, this vulnerability should still be a cause for concern. Note that Docker containers from before February 2023 are not vulnerable to the credential disclosure. Added Reference MITRE https://owncloud.org/security [No types assigned] Added Reference MITRE https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ [No types assigned] Added CVSS V3.1 MITRE AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2023-49103
is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2023-49103
weaknesses.
Exploit Prediction
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.
95.04 }} 0.12%
score
0.99490
percentile