NVD disclosure day

Published threat advisories for November 21, 2023

CVE advisoryKnown Exploit

CVE-2023-49105

ownCloud Server Pre-signed URL Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

ownCloud software has a vulnerability where an unauthenticated attacker can access, modify, or delete any file by knowing a victim's username and exploiting pre-signed URLs when a signing-key is not configured. This could lead to unauthorized data access or alteration.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-49103

ownCloud GraphAPI Information Disclosure Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the ownCloud graphapi app can expose sensitive system details, including credentials. This poses a business risk by potentially allowing attackers unauthorized access to organizational data and systems. Updates are recommended to address this exposure.

• CISA KEV