An issue was discovered in ownCloud owncloud/core before...
Critical severity
Unreviewed
Published
Nov 22, 2023
to the GitHub Advisory Database
•
Updated Apr 2, 2025
Description
Published by the National Vulnerability Database
Nov 21, 2023
Published to the GitHub Advisory Database
Nov 22, 2023
Last updated
Apr 2, 2025
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
References