TROYANOSYVIRUS
Back to CVEs

CVE-2023-49103

CRITICALCISA KEV
10.0

Description

An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system. Therefore, even if ownCloud is not running in a containerized environment, this vulnerability should still be a cause for concern. Note that Docker containers from before February 2023 are not vulnerable to the credential disclosure.

CVE Details

CVSS v3.1 Score10.0
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published11/21/2023
Last Modified10/31/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorownCloud
ProductownCloud graphapi
Vulnerability NameownCloud graphapi Information Disclosure Vulnerability
KEV Date Added2023-11-30
Remediation Due Date2023-12-21
Ransomware UseUnknown

Affected Products

owncloud:graph_api

Weaknesses (CWE)

CWE-200

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.