CVE-2023-49105
ownCloud Server Pre-signed URL Authentication Bypass Vulnerability
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
ownCloud software has a vulnerability where an unauthenticated attacker can access, modify, or delete any file by knowing a victim's username and exploiting pre-signed URLs when a signing-key is not configured. This could lead to unauthorized data access or alteration.