privacysavvy

privacysavvy

Thursday, November 30, 2023

[New post] CVE-2023-49103 Detection: A Critical Vulnerability In OwnClouds Graph API App Leveraged For In-The-Wild Attacks

Site logo image Malware Devil posted: "Hot on the heels of the Zimbra zero-day vulnerability, another critical security flaw affecting popular software comes to the scene. The open-source file-sharing software ownCloud has recently disclosed a trio of disturbing security holes in its products." Malware Devil

CVE-2023-49103 Detection: A Critical Vulnerability In OwnClouds Graph API App Leveraged For In-The-Wild Attacks

Malware Devil

Nov 30

Hot on the heels of the Zimbra zero-day vulnerability, another critical security flaw affecting popular software comes to the scene. The open-source file-sharing software ownCloud has recently disclosed a trio of disturbing security holes in its products. Among them, the max severity vulnerability tracked as CVE-2023-49103 gained the CVSS score of 10 due to the ease of its exploitation, enabling adversaries to access user login details and collect sensitive data. The mass exploitation of CVE-2023-49103 in real-world intrusions requires ultra-responsiveness from defenders to help organizations promptly respond to the threat.

Detect CVE-2023-49103 Exploitation Attempts

Critical vulnerabilities in open-source software products pose a significant menace to cyber defenders due to the broad geography of potential victims and the high possibility of mass exploitation in the wild. To act faster than threat actors and defend proactively, security professionals require a reliable source of detection content and advanced threat detection tools. To identify possible attacks leveraging CVE-2023-49103 exploits, SOC Prime Platform offers a curated detection rule by our keen Threat Bounty developer Wirapong Petshagun.

Possible Critical Vulnerability of The Graphapi App in ownCloud (CVE-2023-49103) Exploitation Attempt (via webserver)

This Sigma rule detects a potential exploitation attempt targeting The Graph API App of ownCloud bug (CVE-2023-49103). The detection is mapped to MITRE ATT&CK® addressing the Initial Access tactic with the Exploit Public-Facing Application (T1190) technique. Automatically convert detection code to dozens of SIEM, EDR, XDR, and Data Lake solutions and explore relevant CTI for streamlined threat research.

To view the full list of detection rules addressing the exploitation of emerging and critical vulnerabilities, hit the Explore Detections button below. All rules are accompanied by detailed metadata, including CTI links, ATT&CK mapping, triage recommendations, and more. 

Explore Detections

Enthusiastic to join the collective cyber defense and obtain financial benefits for your contribution? Register to SOC Prime Threat Bounty program for cyber defenders, contribute your own detection rules, code your future CV, network with industry experts, and receive payouts for your input.

CVE-2023-49103 Analysis

A critical vulnerability in ownCloud, a widely-used business tool for enterprise-grade file sync and sharing, identified as CVE-2023-49103 is being massively leveraged by hackers in ongoing attacks. Successful exploitation attempts enable attackers to steal sensitive info, such as admin and mail server credentials, or license keys, exposing global organizations to data breach risks. 

OwnCloud recently issued a public notice, revealing a maximum severe vulnerability rated with a top CVSS score of 10. CVE-2023-49103 impacts OwnCloud's Graph API app versions 0.2.0 through 0.3.0. The app's dependency on an external library gives attackers the green light to manipulate the API-provided URL. 

GreyNoise team provided in-depth research into the CVE-2023-49103 exploit details based on the observed in-the-wild attacks weaponizing the flaw in the third decade of November.  

Apart from CVE-2023-49103, OwnCloud also reported two other critical security flaws in its software — CVE-2023-49105, an authentication bypass in the WebDAV API with a CVSS score of 9.8, and CVE-2023-49104, a subdomain validation bypass vulnerability earning a lower CVSS rating of 8.7.

OwnCloud stresses that simply removing the Graph API app cannot resolve all the issues. As recommended CVE-2023-49103 mitigation measures, defenders suggest removing the file "owncloud/apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php," deactivating the "phpinfo" function in Docker containers, and fully updating potentially compromised credentials. The ownCloud admins are strongly recommended to instantly apply the suggested fixes and library updates to remediate the risks.

All three above-mentioned vulnerabilities can potentially expose organizations to data breaches and phishing attacks while posing threats to the system integrity.

The increasing volumes of disclosed vulnerabilities impacting popular software products encourage organizations to continuously strengthen their cyber defense capabilities. Rely on the Threat Detection Marketplace to reach the latest detection algorithms against CVEs, zero-days, and emerging threats of any scale and seamlessly implement the proactive cybersecurity strategy into your organization's procedures.

The post CVE-2023-49103 Detection: A Critical Vulnerability in OwnCloud's Graph API App Leveraged for in-the-Wild Attacks appeared first on SOC Prime.

Comment

Manage your email settings or unsubscribe.

Trouble clicking? Copy and paste this URL into your browser:
https://devi.ly/cve-2023-49103-detection-a-critical-vulnerability-in-ownclouds-graph-api-app-leveraged-for-in-the-wild-attacks/

WordPress.com and Jetpack Logos

Get the Jetpack app to use Reader anywhere, anytime

Follow your favorite sites, save posts to read later, and get real-time notifications for likes and comments.

Download Jetpack on Google Play Download Jetpack from the App Store
WordPress.com on Twitter WordPress.com on Facebook WordPress.com on Instagram WordPress.com on YouTube
WordPress.com Logo and Wordmark title=

Automattic, Inc. - 60 29th St. #343, San Francisco, CA 94110  

at November 30, 2023
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

It's selfless.

Men, taking good care of your health is selfless. ͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ...

  • [New post] After Announcing a New CEO, is Lordstown Motors Worth Buying?
    Editorial Team posted: "To improve its market reputation and streamline its operations, on Aug. 26 electric vehicle (EV) ma...
  • [New post] Norwegian Black Metal Bands – Satanic or Psychotic?
    Dawn ...
  • [New post] Estrazioni Lotto di oggi martedì 30 novembre 2021
    Redazione News posted: "Seguite su Cyberludus.com la diretta delle estrazioni di Lotto, 10eLotto e Superenalotto di martedì...

Search This Blog

  • Home

About Me

privacysavvy
View my complete profile

Report Abuse

Blog Archive

  • February 2026 (7)
  • January 2026 (77)
  • December 2025 (79)
  • November 2025 (73)
  • October 2025 (88)
  • September 2025 (79)
  • August 2025 (71)
  • July 2025 (89)
  • June 2025 (78)
  • May 2025 (95)
  • April 2025 (85)
  • March 2025 (78)
  • February 2025 (31)
  • January 2025 (50)
  • December 2024 (39)
  • November 2024 (42)
  • October 2024 (54)
  • September 2024 (83)
  • August 2024 (2665)
  • July 2024 (3210)
  • June 2024 (2908)
  • May 2024 (3025)
  • April 2024 (3132)
  • March 2024 (3115)
  • February 2024 (2893)
  • January 2024 (3169)
  • December 2023 (3031)
  • November 2023 (3021)
  • October 2023 (2352)
  • September 2023 (1900)
  • August 2023 (2009)
  • July 2023 (1878)
  • June 2023 (1594)
  • May 2023 (1716)
  • April 2023 (1657)
  • March 2023 (1737)
  • February 2023 (1597)
  • January 2023 (1574)
  • December 2022 (1543)
  • November 2022 (1684)
  • October 2022 (1617)
  • September 2022 (1310)
  • August 2022 (1676)
  • July 2022 (1375)
  • June 2022 (1458)
  • May 2022 (1297)
  • April 2022 (1464)
  • March 2022 (1491)
  • February 2022 (1249)
  • January 2022 (1282)
  • December 2021 (1663)
  • November 2021 (3139)
  • October 2021 (3253)
  • September 2021 (3136)
  • August 2021 (732)
Powered by Blogger.