CVE-2023-49105: ownCloud ownCloud
ownCloud包含一個不適當的認證弱點,如果受害人的使用者名稱已知,且受害人沒有簽名金鑰配置,允許攻擊者訪問,修改,或刪除任何檔案而無需認證。
CISA (English)
ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.
- 廠商
- ownCloud
- 產品
- ownCloud
- 漏洞
- ownCloud Improper Authentication Vulnerability
- 加入日期
- 2026年8月27日
- CISA 修補期限(美國聯邦機關)
- 2026年8月30日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-287
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02