* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Thursday, November 13, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    ‘The Price Is Right’ Contestant Said She ‘Manifested’ Her $100,000 Win – CBS 19 News

    ‘The Price Is Right’ Contestant Said She ‘Manifested’ Her $100,000 Win – CBS 19 News

    Billy Bob Thornton says Hollywood told him he ‘wasn’t southern enough’: ‘I am just off the turnip truck’ – Yahoo

    Billy Bob Thornton says Hollywood told him he ‘wasn’t southern enough’: ‘I am just off the turnip truck’ – Yahoo

    Nov. 13 Vallejo/Vacaville Arts/Entertainment Source: Activities – Times Herald Online

    Nov. 13 Vallejo/Vacaville Arts/Entertainment Source: Activities – Times Herald Online

    New Orleans Museum of Art director gets a French award started by Napoleon Bonaparte – NOLA.com

    New Orleans Museum of Art director gets a French award started by Napoleon Bonaparte – NOLA.com

    ‘Little House on the Prairie’ stars reunite for iconic show’s 50th anniversary – Spectrum News

    ‘Little House on the Prairie’ stars reunite for iconic show’s 50th anniversary – Spectrum News

    Die My Love to Rosalía’s Lux: your complete entertainment guide to the week ahead – The Guardian

    Die My Love to Rosalía’s Lux: your complete entertainment guide to the week ahead – The Guardian

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    mPower Technology opens automated solar module line for space – pv magazine USA

    MPower Technology Launches Cutting-Edge Automated Solar Module Line for Space Applications

    Two Tigers land Liberty League All-Conference honors – Rochester Institute of Technology Athletics

    Two Tigers land Liberty League All-Conference honors – Rochester Institute of Technology Athletics

    Green Technology Book: Solutions for confronting climate disasters – Part 1: Water-related disasters – WIPO – World Intellectual Property Organization

    Green Technology Book: Solutions for confronting climate disasters – Part 1: Water-related disasters – WIPO – World Intellectual Property Organization

    Reimagining cybersecurity in the era of AI and quantum – MIT Technology Review

    Reimagining cybersecurity in the era of AI and quantum – MIT Technology Review

    Davis R M Inc. Has $16.67 Million Holdings in Microchip Technology Incorporated $MCHP – MarketBeat

    Davis R M Inc. Amplifies Investment with $16.67 Million Stake in Microchip Technology

    World Wide Technology Championship Full Prize Money Payout 2025 – Golf Monthly

    World Wide Technology Championship Full Prize Money Payout 2025 – Golf Monthly

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    ‘The Price Is Right’ Contestant Said She ‘Manifested’ Her $100,000 Win – CBS 19 News

    ‘The Price Is Right’ Contestant Said She ‘Manifested’ Her $100,000 Win – CBS 19 News

    Billy Bob Thornton says Hollywood told him he ‘wasn’t southern enough’: ‘I am just off the turnip truck’ – Yahoo

    Billy Bob Thornton says Hollywood told him he ‘wasn’t southern enough’: ‘I am just off the turnip truck’ – Yahoo

    Nov. 13 Vallejo/Vacaville Arts/Entertainment Source: Activities – Times Herald Online

    Nov. 13 Vallejo/Vacaville Arts/Entertainment Source: Activities – Times Herald Online

    New Orleans Museum of Art director gets a French award started by Napoleon Bonaparte – NOLA.com

    New Orleans Museum of Art director gets a French award started by Napoleon Bonaparte – NOLA.com

    ‘Little House on the Prairie’ stars reunite for iconic show’s 50th anniversary – Spectrum News

    ‘Little House on the Prairie’ stars reunite for iconic show’s 50th anniversary – Spectrum News

    Die My Love to Rosalía’s Lux: your complete entertainment guide to the week ahead – The Guardian

    Die My Love to Rosalía’s Lux: your complete entertainment guide to the week ahead – The Guardian

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    mPower Technology opens automated solar module line for space – pv magazine USA

    MPower Technology Launches Cutting-Edge Automated Solar Module Line for Space Applications

    Two Tigers land Liberty League All-Conference honors – Rochester Institute of Technology Athletics

    Two Tigers land Liberty League All-Conference honors – Rochester Institute of Technology Athletics

    Green Technology Book: Solutions for confronting climate disasters – Part 1: Water-related disasters – WIPO – World Intellectual Property Organization

    Green Technology Book: Solutions for confronting climate disasters – Part 1: Water-related disasters – WIPO – World Intellectual Property Organization

    Reimagining cybersecurity in the era of AI and quantum – MIT Technology Review

    Reimagining cybersecurity in the era of AI and quantum – MIT Technology Review

    Davis R M Inc. Has $16.67 Million Holdings in Microchip Technology Incorporated $MCHP – MarketBeat

    Davis R M Inc. Amplifies Investment with $16.67 Million Stake in Microchip Technology

    World Wide Technology Championship Full Prize Money Payout 2025 – Golf Monthly

    World Wide Technology Championship Full Prize Money Payout 2025 – Golf Monthly

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

A critical vulnerability in ownCloud servers is being exploited en masse

November 30, 2023
in Technology
A critical vulnerability in ownCloud servers is being exploited en masse
Share on FacebookShare on Twitter

TechSpot is celebrating its 25th anniversary. TechSpot means tech analysis and advice you can trust.

Facepalm: OwnCloud is an open-source software designed for sharing and syncing files in distributed and federated enterprise environments. The tool provides collaboration and document-sharing services, but a recently disclosed vulnerability has extended its “sharing” capabilities in an unintended way, compromising sensitive data.

This past week, ownCloud publicly disclosed a critical vulnerability in the “graphapi” app. The security flaw is being tracked with the highest level of risk on the CVE scale (10) as CVE-2023-49103. A week later, security researchers have now started to witness what could amount to “mass” exploitation of this extremely dangerous flaw.

According to ownCloud’s official advisory, the CVE-2023-49103 issue stems from a third-party library used by the graphapi app (GetPhpInfo.php). The library provides a URL that, when accessed, reveals the configuration details of the PHP environment. The provided information also includes all the environment variables of the webserver, ownCloud said.

The issue mostly arises in containerized deployments of ownCloud, where the environment variables disclosed by getphpinfo.php “may include” sensitive data such as admin passwords, server credentials, and license keys. Simply disabling the graphapi app doesn’t eliminate the vulnerability, as the flawed library still provides the secret-disclosing URL, according to ownCloud.

Aside from disclosing server secrets, the vulnerable phpinfo library can expose other potentially sensitive configuration details that an attacker could exploit to gather further information about the system. Even if ownCloud is not running in a containerized environment, the advisory warns, server admins should still be concerned about the vulnerability’s potential outcomes.

According to security company GreyNoise, the CVE-2023-49103 flaw is now actively being exploited by cyber-criminals. Researchers describe a “mass exploitation” of the flaw in the wild, which they detected as early as November 25, 2023. Black hat hackers are seeking passwords, mail server credentials, and license keys, which the detailed vulnerability would gladly reveal to anyone.

While the company is working on “various hardenings” in future core releases to avoid similar vulnerabilities, ownCloud advised users to delete the flawed GetPhpInfo.php library from their servers. Furthermore, the phpinfo function was disabled in the containers the German company directly provides to its enterprise customers.

Further advice provided by ownCloud includes a global reset of server “secrets,” including passwords, credentials, and access keys. In addition to CVE-2023-49103, GreyNoise remarks that ownCloud recently disclosed additional critical vulnerabilities. The flaws include an authentication bypass issue with a 9.8 CVE score (CVE-2023-49105) and a highly dangerous flaw related to the oauth2 app (CVE-2023-49104).

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : TechSpot – https://www.techspot.com/news/100994-critical-vulnerability-owncloud-servers-exploited-en-masse.html

Tags: criticaltechnologyvulnerability
Previous Post

Where to watch Christmas at Graceland holiday special

Next Post

Court mandates Epic and Google to settlement talks before concluding antitrust lawsuit

Nine Emory faculty recognized among world’s most influential researchers in 2025 | Emory University | Atlanta GA – Emory University

Nine Emory Faculty Named Among the World’s Most Influential Researchers in 2025

November 13, 2025
Trump Dismisses Economic Anxiety at His Own Peril – National Review

Trump Dismisses Economic Warnings-A Risk That Could Backfire

November 13, 2025
‘The Price Is Right’ Contestant Said She ‘Manifested’ Her $100,000 Win – CBS 19 News

‘The Price Is Right’ Contestant Said She ‘Manifested’ Her $100,000 Win – CBS 19 News

November 13, 2025
Louisiana health system CEO named to AHA Board of Trustees – American Hospital Association

Louisiana Health System CEO Earns Coveted Spot on Prestigious AHA Board of Trustees

November 13, 2025
Jack Schlossberg, Scion of the Kennedy Family, Gives Politics a Try – The New York Times

Jack Schlossberg, Kennedy Family Heir, Launches His Political Journey

November 13, 2025
Plant traits and associated ecological data from Afromontane grasslands of Maloti-Drakensberg, South Africa – Nature

Plant traits and associated ecological data from Afromontane grasslands of Maloti-Drakensberg, South Africa – Nature

November 12, 2025
L’Oréal USA Announces 2025 For Women in Science Awardees, Underscoring Commitment to Advancing Careers in STEM – PR Newswire

L’Oréal USA Announces 2025 Women in Science Awardees, Celebrating the Future of Women in STEM

November 12, 2025
Top Science Committee Democrat calls for halt to Goddard facility closures – SpaceNews

Top Science Committee Democrat calls for halt to Goddard facility closures – SpaceNews

November 12, 2025
Review: Buffalo Trace Just Dropped the Best $40 High-Proof Rye Whiskey on the Market – Yahoo

Buffalo Trace Unveils the Best $40 High-Proof Rye Whiskey You Can Buy

November 12, 2025
mPower Technology opens automated solar module line for space – pv magazine USA

MPower Technology Launches Cutting-Edge Automated Solar Module Line for Space Applications

November 12, 2025

Categories

Archives

November 2025
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
« Oct    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (916)
  • Economy (937)
  • Entertainment (21,810)
  • General (18,146)
  • Health (9,976)
  • Lifestyle (947)
  • News (22,149)
  • People (938)
  • Politics (948)
  • Science (16,149)
  • Sports (21,436)
  • Technology (15,916)
  • World (922)

Recent News

Nine Emory faculty recognized among world’s most influential researchers in 2025 | Emory University | Atlanta GA – Emory University

Nine Emory Faculty Named Among the World’s Most Influential Researchers in 2025

November 13, 2025
Trump Dismisses Economic Anxiety at His Own Peril – National Review

Trump Dismisses Economic Warnings-A Risk That Could Backfire

November 13, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version