Executive brief
The ownCloud graphapi app relies on a third-party library that exposes a URL revealing phpinfo() details. In containerized environments, this can disclose sensitive environment variables including administrative passwords, mail server credentials, and license keys.
Affected products
- ownCloud graphapi 0.2.x before 0.2.1, 0.3.x before 0.3.1
Timeline
- 2023-11-30: disclosed
- 2023-11-30: kev added: Added to CISA KEV catalog
- 2023-11-30: exploited: Reported as exploited in the wild at time of publication