* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Sunday, September 14, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Ryan Reynolds reveals he called a journalist who said mean things about John Candy – yahoo.com

    Ryan Reynolds Reveals the Moment He Stood Up to a Journalist Who Insulted John Candy

    Entertainment Community Fund Launches Program Supporting Entrepreneurs – Playbill

    Entertainment Community Fund Unveils Exciting New Program to Empower Entrepreneurs

    Behind the turntables: DJ Johnny Kage’s story of perseverance – yahoo.com

    Behind the Turntables: DJ Johnny Kage’s Inspiring Journey of Perseverance

    The other WWE star James Gunn wanted for Peacemaker instead of John Cena – yahoo.com

    The WWE Star James Gunn Originally Wanted for Peacemaker Instead of John Cena

    Quinta Brunson, John Stamos Join Entertainment and Technology Summit – Variety

    Quinta Brunson and John Stamos to Headline Thrilling Entertainment and Technology Summit

    ‘Breaking Bad’ star arrested for incident with neighbor. Here’s the latest – PennLive.com

    Breaking Bad’ Star Arrested Following Neighbor Dispute: Latest Updates

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    What if artificial intelligence is just a “normal” technology? – The Economist

    What if artificial intelligence is just a “normal” technology? – The Economist

    Lincoln Trail College Receives $100,000 Grant from Marathon Petroleum Corporation for Technology Center – wwbl.com

    Lincoln Trail College Lands $100,000 Grant from Marathon Petroleum to Elevate Technology Center

    Aston Martin to integrate Pirelli’s cyber tyre technology in future models – Just Auto

    Aston Martin to Revolutionize Future Models with Pirelli’s Cutting-Edge Cyber Tyre Technology

    Figure Technology’s stock sizzles after IPO, as investors stay hungry for crypto deals – MarketWatch

    Figure Technology’s Stock Skyrockets After IPO Amid Surging Crypto Investor Excitement

    AI is the ‘most transformational technology’ in our lifetime, AMD CEO argues – Fox Business

    AMD CEO Declares AI the Most Transformative Technology of Our Era

    PAR Technology (PAR) Unveils AI-Powered Assistant Enhancing Restaurant Operations and Customer Engagement – simplywall.st

    PAR Technology Unveils AI-Powered Assistant to Revolutionize Restaurant Operations and Boost Customer Engagement

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Ryan Reynolds reveals he called a journalist who said mean things about John Candy – yahoo.com

    Ryan Reynolds Reveals the Moment He Stood Up to a Journalist Who Insulted John Candy

    Entertainment Community Fund Launches Program Supporting Entrepreneurs – Playbill

    Entertainment Community Fund Unveils Exciting New Program to Empower Entrepreneurs

    Behind the turntables: DJ Johnny Kage’s story of perseverance – yahoo.com

    Behind the Turntables: DJ Johnny Kage’s Inspiring Journey of Perseverance

    The other WWE star James Gunn wanted for Peacemaker instead of John Cena – yahoo.com

    The WWE Star James Gunn Originally Wanted for Peacemaker Instead of John Cena

    Quinta Brunson, John Stamos Join Entertainment and Technology Summit – Variety

    Quinta Brunson and John Stamos to Headline Thrilling Entertainment and Technology Summit

    ‘Breaking Bad’ star arrested for incident with neighbor. Here’s the latest – PennLive.com

    Breaking Bad’ Star Arrested Following Neighbor Dispute: Latest Updates

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    What if artificial intelligence is just a “normal” technology? – The Economist

    What if artificial intelligence is just a “normal” technology? – The Economist

    Lincoln Trail College Receives $100,000 Grant from Marathon Petroleum Corporation for Technology Center – wwbl.com

    Lincoln Trail College Lands $100,000 Grant from Marathon Petroleum to Elevate Technology Center

    Aston Martin to integrate Pirelli’s cyber tyre technology in future models – Just Auto

    Aston Martin to Revolutionize Future Models with Pirelli’s Cutting-Edge Cyber Tyre Technology

    Figure Technology’s stock sizzles after IPO, as investors stay hungry for crypto deals – MarketWatch

    Figure Technology’s Stock Skyrockets After IPO Amid Surging Crypto Investor Excitement

    AI is the ‘most transformational technology’ in our lifetime, AMD CEO argues – Fox Business

    AMD CEO Declares AI the Most Transformative Technology of Our Era

    PAR Technology (PAR) Unveils AI-Powered Assistant Enhancing Restaurant Operations and Customer Engagement – simplywall.st

    PAR Technology Unveils AI-Powered Assistant to Revolutionize Restaurant Operations and Boost Customer Engagement

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

A critical vulnerability in ownCloud servers is being exploited en masse

November 30, 2023
in Technology
A critical vulnerability in ownCloud servers is being exploited en masse
Share on FacebookShare on Twitter

TechSpot is celebrating its 25th anniversary. TechSpot means tech analysis and advice you can trust.

Facepalm: OwnCloud is an open-source software designed for sharing and syncing files in distributed and federated enterprise environments. The tool provides collaboration and document-sharing services, but a recently disclosed vulnerability has extended its “sharing” capabilities in an unintended way, compromising sensitive data.

This past week, ownCloud publicly disclosed a critical vulnerability in the “graphapi” app. The security flaw is being tracked with the highest level of risk on the CVE scale (10) as CVE-2023-49103. A week later, security researchers have now started to witness what could amount to “mass” exploitation of this extremely dangerous flaw.

According to ownCloud’s official advisory, the CVE-2023-49103 issue stems from a third-party library used by the graphapi app (GetPhpInfo.php). The library provides a URL that, when accessed, reveals the configuration details of the PHP environment. The provided information also includes all the environment variables of the webserver, ownCloud said.

The issue mostly arises in containerized deployments of ownCloud, where the environment variables disclosed by getphpinfo.php “may include” sensitive data such as admin passwords, server credentials, and license keys. Simply disabling the graphapi app doesn’t eliminate the vulnerability, as the flawed library still provides the secret-disclosing URL, according to ownCloud.

Aside from disclosing server secrets, the vulnerable phpinfo library can expose other potentially sensitive configuration details that an attacker could exploit to gather further information about the system. Even if ownCloud is not running in a containerized environment, the advisory warns, server admins should still be concerned about the vulnerability’s potential outcomes.

According to security company GreyNoise, the CVE-2023-49103 flaw is now actively being exploited by cyber-criminals. Researchers describe a “mass exploitation” of the flaw in the wild, which they detected as early as November 25, 2023. Black hat hackers are seeking passwords, mail server credentials, and license keys, which the detailed vulnerability would gladly reveal to anyone.

While the company is working on “various hardenings” in future core releases to avoid similar vulnerabilities, ownCloud advised users to delete the flawed GetPhpInfo.php library from their servers. Furthermore, the phpinfo function was disabled in the containers the German company directly provides to its enterprise customers.

Further advice provided by ownCloud includes a global reset of server “secrets,” including passwords, credentials, and access keys. In addition to CVE-2023-49103, GreyNoise remarks that ownCloud recently disclosed additional critical vulnerabilities. The flaws include an authentication bypass issue with a 9.8 CVE score (CVE-2023-49105) and a highly dangerous flaw related to the oauth2 app (CVE-2023-49104).

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : TechSpot – https://www.techspot.com/news/100994-critical-vulnerability-owncloud-servers-exploited-en-masse.html

Tags: criticaltechnologyvulnerability
Previous Post

Where to watch Christmas at Graceland holiday special

Next Post

Court mandates Epic and Google to settlement talks before concluding antitrust lawsuit

World Athletics Championships 2025: Ryan Crouser, in only competition of year, wins third straight shot put world title – Olympics.com

World Athletics Championships 2025: Ryan Crouser, in only competition of year, wins third straight shot put world title – Olympics.com

September 14, 2025
A potentially K-shaped economy creates dilemmas for the Fed – The Hill

Navigating a K-Shaped Economy: The Fed’s Tough Road Ahead

September 14, 2025
Ryan Reynolds reveals he called a journalist who said mean things about John Candy – yahoo.com

Ryan Reynolds Reveals the Moment He Stood Up to a Journalist Who Insulted John Candy

September 14, 2025
The Surprising Health Benefits of Doing Jigsaw Puzzles, According to Experts – marthastewart.com

Unlock Unexpected Health Benefits by Doing Jigsaw Puzzles

September 14, 2025
Foreign hack of John Bolton’s AOL account cited as part of reasoning for searching his house – CNN

Foreign hack of John Bolton’s AOL account cited as part of reasoning for searching his house – CNN

September 14, 2025
‘We’ve done it before’: how not to lose hope in the fight against ecological disaster – The Guardian

We’ve Done It Before”: Finding Hope and Strength in the Fight Against Ecological Disaster

September 13, 2025
AI Can Generate Code. Is That a Threat to Computer Science Education? – Education Week

Is AI-Generated Code a Challenge for the Future of Computer Science Education?

September 13, 2025
Aldi’s $7 Salmon & Sweet Potato Dog Food Has Pups Going Wild – yahoo.com

Aldi’s $7 Salmon & Sweet Potato Dog Food Has Pups Going Wild

September 13, 2025
What if artificial intelligence is just a “normal” technology? – The Economist

What if artificial intelligence is just a “normal” technology? – The Economist

September 13, 2025
Saints to sign DL Jonah Williams to active roster – Yahoo Sports

Saints to sign DL Jonah Williams to active roster – Yahoo Sports

September 13, 2025

Categories

Archives

September 2025
MTWTFSS
1234567
891011121314
15161718192021
22232425262728
2930 
« Aug    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (819)
  • Economy (838)
  • Entertainment (21,716)
  • General (17,021)
  • Health (9,882)
  • Lifestyle (853)
  • News (22,149)
  • People (841)
  • Politics (847)
  • Science (16,048)
  • Sports (21,338)
  • Technology (15,820)
  • World (821)

Recent News

World Athletics Championships 2025: Ryan Crouser, in only competition of year, wins third straight shot put world title – Olympics.com

World Athletics Championships 2025: Ryan Crouser, in only competition of year, wins third straight shot put world title – Olympics.com

September 14, 2025
A potentially K-shaped economy creates dilemmas for the Fed – The Hill

Navigating a K-Shaped Economy: The Fed’s Tough Road Ahead

September 14, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version