Junglewise Threat Intelligence

CVE-2023-49103: ownCloud graphapi Information Disclosure Vulnerability

CVE-2023-49103 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2023-11-30

Vendors: ownCloud.

Executive brief

The ownCloud graphapi app relies on a third-party library that exposes a URL revealing phpinfo() details. In containerized environments, this can disclose sensitive environment variables including administrative passwords, mail server credentials, and license keys.

Affected products

  • ownCloud graphapi 0.2.x before 0.2.1, 0.3.x before 0.3.1

Timeline

  • 2023-11-30: disclosed
  • 2023-11-30: kev added: Added to CISA KEV catalog
  • 2023-11-30: exploited: Reported as exploited in the wild at time of publication