{"id":"CVE-2023-49105","details":"An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.","modified":"2026-08-30T03:30:20.700049995Z","published":"2023-11-21T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49105.json","unresolved_ranges":[{"source":"DESCRIPTION","extracted_events":[{"fixed":"10.13.1"}]}],"cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://owncloud.org/security"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-49105"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49105.json"},{"type":"ADVISORY","url":"https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49105"},{"type":"ADVISORY","url":"https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/owncloud/core","events":[{"introduced":"94282d9471e5c786602af512e7207aed6b6e3f8f"},{"fixed":"d06b1d870377662dd9ff327485acc2d3e1991bcb"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"10.6.0"},{"fixed":"10.13.1"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-49105.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N"}]}