* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Wednesday, May 14, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    HG Vora Files Definitive Proxy Materials and Sends Letter to PENN Entertainment, Inc. Shareholders – Business Wire

    HG Vora Takes Action: A Bold Move to Engage PENN Entertainment Shareholders

    Downtown Frederick Partnership announces Alive@Five season lineup – The Frederick News-Post

    Get Ready for Fun: Downtown Frederick’s Exciting Alive@Five Season Lineup Revealed!

    ‘American Idol’ Top 3 revealed as 2 contestants eliminated: Who advanced to the Season 23 finale? – Yahoo

    ‘American Idol’ Top 3 revealed as 2 contestants eliminated: Who advanced to the Season 23 finale? – Yahoo

    60,000 Fans Caused a Small Earthquake Because of One Famous Rock Song – Yahoo

    How 60,000 Fans Rocked the Ground with One Iconic Song!

    Dan Spilo Out at Industry Entertainment After Incident on Set of Alan Ritchson Movie (Exclusive) – The Hollywood Reporter

    Dan Spilo Exits Industry Entertainment Following Controversial Incident on Set of Alan Ritchson Film

    John Legend Says He’s Shocked by Ye’s ‘Descent’ Into ‘Antisemitism’ and ‘Anti-Blackness’ – Yahoo

    John Legend Expresses Shock Over Ye’s Troubling Descent into Antisemitism and Anti-Blackness

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Bridger Photonics Appoints Ryan Sullivan as Chief Technology Officer to Accelerate New Era of Data Insights – Business Wire

    Bridger Photonics Welcomes Ryan Sullivan as CTO to Propel Data Insights into a New Era!

    Michigan Public Policy Survey suggests uncertainty among local officials on AI police surveillance technology – The Michigan Daily

    Local Officials Grapple with Uncertainty Over AI Surveillance Technology in Policing

    Trump Media & Technology Group: When Politics Gets A Ticker Symbol (NASDAQ:DJT) – Seeking Alpha

    Trump Media & Technology Group: When Politics Gets A Ticker Symbol (NASDAQ:DJT) – Seeking Alpha

    GenTech offers coding, AI lessons for elementary students – KTAR.com

    GenTech offers coding, AI lessons for elementary students – KTAR.com

    Arkansas Tech Univeristy-Ozark collision repair technology program re-accredited – Northwest Arkansas Democrat-Gazette

    Arkansas Tech University-Ozark’s Collision Repair Technology Program Earns Re-Accreditation!

    Top Chief Technology Officers to Watch in 2025: SMX’s Anthony Vultaggio – WashingtonExec

    Top Chief Technology Officers to Watch in 2025: SMX’s Anthony Vultaggio – WashingtonExec

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    HG Vora Files Definitive Proxy Materials and Sends Letter to PENN Entertainment, Inc. Shareholders – Business Wire

    HG Vora Takes Action: A Bold Move to Engage PENN Entertainment Shareholders

    Downtown Frederick Partnership announces Alive@Five season lineup – The Frederick News-Post

    Get Ready for Fun: Downtown Frederick’s Exciting Alive@Five Season Lineup Revealed!

    ‘American Idol’ Top 3 revealed as 2 contestants eliminated: Who advanced to the Season 23 finale? – Yahoo

    ‘American Idol’ Top 3 revealed as 2 contestants eliminated: Who advanced to the Season 23 finale? – Yahoo

    60,000 Fans Caused a Small Earthquake Because of One Famous Rock Song – Yahoo

    How 60,000 Fans Rocked the Ground with One Iconic Song!

    Dan Spilo Out at Industry Entertainment After Incident on Set of Alan Ritchson Movie (Exclusive) – The Hollywood Reporter

    Dan Spilo Exits Industry Entertainment Following Controversial Incident on Set of Alan Ritchson Film

    John Legend Says He’s Shocked by Ye’s ‘Descent’ Into ‘Antisemitism’ and ‘Anti-Blackness’ – Yahoo

    John Legend Expresses Shock Over Ye’s Troubling Descent into Antisemitism and Anti-Blackness

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Bridger Photonics Appoints Ryan Sullivan as Chief Technology Officer to Accelerate New Era of Data Insights – Business Wire

    Bridger Photonics Welcomes Ryan Sullivan as CTO to Propel Data Insights into a New Era!

    Michigan Public Policy Survey suggests uncertainty among local officials on AI police surveillance technology – The Michigan Daily

    Local Officials Grapple with Uncertainty Over AI Surveillance Technology in Policing

    Trump Media & Technology Group: When Politics Gets A Ticker Symbol (NASDAQ:DJT) – Seeking Alpha

    Trump Media & Technology Group: When Politics Gets A Ticker Symbol (NASDAQ:DJT) – Seeking Alpha

    GenTech offers coding, AI lessons for elementary students – KTAR.com

    GenTech offers coding, AI lessons for elementary students – KTAR.com

    Arkansas Tech Univeristy-Ozark collision repair technology program re-accredited – Northwest Arkansas Democrat-Gazette

    Arkansas Tech University-Ozark’s Collision Repair Technology Program Earns Re-Accreditation!

    Top Chief Technology Officers to Watch in 2025: SMX’s Anthony Vultaggio – WashingtonExec

    Top Chief Technology Officers to Watch in 2025: SMX’s Anthony Vultaggio – WashingtonExec

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

A critical vulnerability in ownCloud servers is being exploited en masse

November 30, 2023
in Technology
A critical vulnerability in ownCloud servers is being exploited en masse
Share on FacebookShare on Twitter

TechSpot is celebrating its 25th anniversary. TechSpot means tech analysis and advice you can trust.

Facepalm: OwnCloud is an open-source software designed for sharing and syncing files in distributed and federated enterprise environments. The tool provides collaboration and document-sharing services, but a recently disclosed vulnerability has extended its “sharing” capabilities in an unintended way, compromising sensitive data.

This past week, ownCloud publicly disclosed a critical vulnerability in the “graphapi” app. The security flaw is being tracked with the highest level of risk on the CVE scale (10) as CVE-2023-49103. A week later, security researchers have now started to witness what could amount to “mass” exploitation of this extremely dangerous flaw.

According to ownCloud’s official advisory, the CVE-2023-49103 issue stems from a third-party library used by the graphapi app (GetPhpInfo.php). The library provides a URL that, when accessed, reveals the configuration details of the PHP environment. The provided information also includes all the environment variables of the webserver, ownCloud said.

The issue mostly arises in containerized deployments of ownCloud, where the environment variables disclosed by getphpinfo.php “may include” sensitive data such as admin passwords, server credentials, and license keys. Simply disabling the graphapi app doesn’t eliminate the vulnerability, as the flawed library still provides the secret-disclosing URL, according to ownCloud.

Aside from disclosing server secrets, the vulnerable phpinfo library can expose other potentially sensitive configuration details that an attacker could exploit to gather further information about the system. Even if ownCloud is not running in a containerized environment, the advisory warns, server admins should still be concerned about the vulnerability’s potential outcomes.

According to security company GreyNoise, the CVE-2023-49103 flaw is now actively being exploited by cyber-criminals. Researchers describe a “mass exploitation” of the flaw in the wild, which they detected as early as November 25, 2023. Black hat hackers are seeking passwords, mail server credentials, and license keys, which the detailed vulnerability would gladly reveal to anyone.

While the company is working on “various hardenings” in future core releases to avoid similar vulnerabilities, ownCloud advised users to delete the flawed GetPhpInfo.php library from their servers. Furthermore, the phpinfo function was disabled in the containers the German company directly provides to its enterprise customers.

Further advice provided by ownCloud includes a global reset of server “secrets,” including passwords, credentials, and access keys. In addition to CVE-2023-49103, GreyNoise remarks that ownCloud recently disclosed additional critical vulnerabilities. The flaws include an authentication bypass issue with a 9.8 CVE score (CVE-2023-49105) and a highly dangerous flaw related to the oauth2 app (CVE-2023-49104).

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : TechSpot – https://www.techspot.com/news/100994-critical-vulnerability-owncloud-servers-exploited-en-masse.html

Tags: criticaltechnologyvulnerability
Previous Post

Where to watch Christmas at Graceland holiday special

Next Post

Court mandates Epic and Google to settlement talks before concluding antitrust lawsuit

Center for Ecology-Based Economy to host climate solution event – Lewiston Sun Journal

Join Us for an Inspiring Climate Solutions Event!

May 14, 2025
Executive order jeopardizes School of Information and Library Science research funding – – The Daily Tar Heel

Executive order jeopardizes School of Information and Library Science research funding – – The Daily Tar Heel

May 14, 2025
What’s hiding under Antarctica’s ice? – Live Science

What’s hiding under Antarctica’s ice? – Live Science

May 14, 2025
“Stand Up Paddleboard” Demonstration and Kayaks Available – swiowanewssource.com

Experience the Thrill: Join Us for a Stand Up Paddleboard and Kayak Adventure!

May 14, 2025
China, Brazil agree to defend multipolar world order amid Trump tariff turmoil – South China Morning Post

China and Brazil Unite to Champion a Multipolar World Amid Trump’s Tariff Turmoil

May 14, 2025
Trump tariffs have little impact on prices so far, defying grim forecasts – Politico

Trump Tariffs: Surprisingly Minimal Impact on Prices Defies Expectations

May 14, 2025
HG Vora Files Definitive Proxy Materials and Sends Letter to PENN Entertainment, Inc. Shareholders – Business Wire

HG Vora Takes Action: A Bold Move to Engage PENN Entertainment Shareholders

May 14, 2025
Summit County health department braces for federal cuts, amount uncertain – KPCW

Summit County health department braces for federal cuts, amount uncertain – KPCW

May 14, 2025
Trump’s Middle East trip: President plans to lift Syria sanctions as he touts Saudi Arabia deals – CNN

Trump’s Middle East trip: President plans to lift Syria sanctions as he touts Saudi Arabia deals – CNN

May 13, 2025
Bridger Photonics Appoints Ryan Sullivan as Chief Technology Officer to Accelerate New Era of Data Insights – Business Wire

Bridger Photonics Welcomes Ryan Sullivan as CTO to Propel Data Insights into a New Era!

May 13, 2025

Categories

Archives

May 2025
MTWTFSS
 1234
567891011
12131415161718
19202122232425
262728293031 
« Apr    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (607)
  • Economy (618)
  • Entertainment (21,531)
  • General (15,214)
  • Health (9,661)
  • Lifestyle (624)
  • News (22,149)
  • People (621)
  • Politics (625)
  • Science (15,841)
  • Sports (21,128)
  • Technology (15,609)
  • World (609)

Recent News

Center for Ecology-Based Economy to host climate solution event – Lewiston Sun Journal

Join Us for an Inspiring Climate Solutions Event!

May 14, 2025
Executive order jeopardizes School of Information and Library Science research funding – – The Daily Tar Heel

Executive order jeopardizes School of Information and Library Science research funding – – The Daily Tar Heel

May 14, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version