* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Saturday, October 25, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    General Hospital’s Rena Sofer Exits as Lois — But the Door Isn’t Closed – Yahoo

    General Hospital’s Rena Sofer Exits as Lois — But the Door Isn’t Closed – Yahoo

    CNN Launches New Show – What to Know About Host Elex Michaelson – Central Oregon Daily

    Get to Know Elex Michaelson: The Dynamic New Host Taking CNN by Storm

    Johnny Depp Set To Finally Make His Big Hollywood Comeback After Amber Heard Controversy – Yahoo

    Johnny Depp Set for a Triumphant Hollywood Comeback Following Amber Heard Controversy

    ‘Chainsaw Man — The Movie: Reze Arc’ Review: Hit Manga Gets an Ultra-Violent, Surprisingly Emotional Big-Screen Adaptation – Yahoo

    Chainsaw Man – The Movie: Reze Arc Review: A Brutal and Unexpectedly Emotional Big-Screen Adaptation

    Reba McEntire Details Personal Relationship With Late Stepson Brandon Blackstock – KNDU

    Reba McEntire Shares Emotional Tribute to Her Late Stepson Brandon Blackstock

    Sacramento city leaders approve adding 2 entertainment zones in midtown – CBS News

    Sacramento City Leaders Approve Two Thrilling New Entertainment Zones in Midtown

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Comments to EU Regarding the Draft Revised Technology Transfer Block Exemption Regulation and Technology Transfer Guidelines – Information Technology and Innovation Foundation

    Have Your Say: Share Your Thoughts on the Draft Revised Technology Transfer Block Exemption Regulation and Guidelines

    Ghost Tapping is exploiting tap-to-pay technology in order to steal your money; what your need to know – ABC7 New York

    Ghost Tapping: How Thieves Are Using Tap-to-Pay Technology to Steal Your Money and What You Need to Know

    New technology for grading and packing dates – FreshPlaza

    Revolutionary Technology Transforms Date Grading and Packing Process

    Project underway to upgrade technology on 911 towers in Kanawha County – WCHS

    Kanawha County Launches Major Upgrade to 911 Tower Technology

    Next steps: Technology opens new options for greater mobility – Missouri Independent

    Next Steps: How Technology is Opening Exciting New Doors to Greater Mobility

    Rydberg Technologies Inc. Announces Launch of Rydberg Photonics in Berlin – The Quantum Insider

    Rydberg Technologies Launches Exciting New Photonics Division in Berlin

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    General Hospital’s Rena Sofer Exits as Lois — But the Door Isn’t Closed – Yahoo

    General Hospital’s Rena Sofer Exits as Lois — But the Door Isn’t Closed – Yahoo

    CNN Launches New Show – What to Know About Host Elex Michaelson – Central Oregon Daily

    Get to Know Elex Michaelson: The Dynamic New Host Taking CNN by Storm

    Johnny Depp Set To Finally Make His Big Hollywood Comeback After Amber Heard Controversy – Yahoo

    Johnny Depp Set for a Triumphant Hollywood Comeback Following Amber Heard Controversy

    ‘Chainsaw Man — The Movie: Reze Arc’ Review: Hit Manga Gets an Ultra-Violent, Surprisingly Emotional Big-Screen Adaptation – Yahoo

    Chainsaw Man – The Movie: Reze Arc Review: A Brutal and Unexpectedly Emotional Big-Screen Adaptation

    Reba McEntire Details Personal Relationship With Late Stepson Brandon Blackstock – KNDU

    Reba McEntire Shares Emotional Tribute to Her Late Stepson Brandon Blackstock

    Sacramento city leaders approve adding 2 entertainment zones in midtown – CBS News

    Sacramento City Leaders Approve Two Thrilling New Entertainment Zones in Midtown

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Comments to EU Regarding the Draft Revised Technology Transfer Block Exemption Regulation and Technology Transfer Guidelines – Information Technology and Innovation Foundation

    Have Your Say: Share Your Thoughts on the Draft Revised Technology Transfer Block Exemption Regulation and Guidelines

    Ghost Tapping is exploiting tap-to-pay technology in order to steal your money; what your need to know – ABC7 New York

    Ghost Tapping: How Thieves Are Using Tap-to-Pay Technology to Steal Your Money and What You Need to Know

    New technology for grading and packing dates – FreshPlaza

    Revolutionary Technology Transforms Date Grading and Packing Process

    Project underway to upgrade technology on 911 towers in Kanawha County – WCHS

    Kanawha County Launches Major Upgrade to 911 Tower Technology

    Next steps: Technology opens new options for greater mobility – Missouri Independent

    Next Steps: How Technology is Opening Exciting New Doors to Greater Mobility

    Rydberg Technologies Inc. Announces Launch of Rydberg Photonics in Berlin – The Quantum Insider

    Rydberg Technologies Launches Exciting New Photonics Division in Berlin

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

A critical vulnerability in ownCloud servers is being exploited en masse

November 30, 2023
in Technology
A critical vulnerability in ownCloud servers is being exploited en masse
Share on FacebookShare on Twitter

TechSpot is celebrating its 25th anniversary. TechSpot means tech analysis and advice you can trust.

Facepalm: OwnCloud is an open-source software designed for sharing and syncing files in distributed and federated enterprise environments. The tool provides collaboration and document-sharing services, but a recently disclosed vulnerability has extended its “sharing” capabilities in an unintended way, compromising sensitive data.

This past week, ownCloud publicly disclosed a critical vulnerability in the “graphapi” app. The security flaw is being tracked with the highest level of risk on the CVE scale (10) as CVE-2023-49103. A week later, security researchers have now started to witness what could amount to “mass” exploitation of this extremely dangerous flaw.

According to ownCloud’s official advisory, the CVE-2023-49103 issue stems from a third-party library used by the graphapi app (GetPhpInfo.php). The library provides a URL that, when accessed, reveals the configuration details of the PHP environment. The provided information also includes all the environment variables of the webserver, ownCloud said.

The issue mostly arises in containerized deployments of ownCloud, where the environment variables disclosed by getphpinfo.php “may include” sensitive data such as admin passwords, server credentials, and license keys. Simply disabling the graphapi app doesn’t eliminate the vulnerability, as the flawed library still provides the secret-disclosing URL, according to ownCloud.

Aside from disclosing server secrets, the vulnerable phpinfo library can expose other potentially sensitive configuration details that an attacker could exploit to gather further information about the system. Even if ownCloud is not running in a containerized environment, the advisory warns, server admins should still be concerned about the vulnerability’s potential outcomes.

According to security company GreyNoise, the CVE-2023-49103 flaw is now actively being exploited by cyber-criminals. Researchers describe a “mass exploitation” of the flaw in the wild, which they detected as early as November 25, 2023. Black hat hackers are seeking passwords, mail server credentials, and license keys, which the detailed vulnerability would gladly reveal to anyone.

While the company is working on “various hardenings” in future core releases to avoid similar vulnerabilities, ownCloud advised users to delete the flawed GetPhpInfo.php library from their servers. Furthermore, the phpinfo function was disabled in the containers the German company directly provides to its enterprise customers.

Further advice provided by ownCloud includes a global reset of server “secrets,” including passwords, credentials, and access keys. In addition to CVE-2023-49103, GreyNoise remarks that ownCloud recently disclosed additional critical vulnerabilities. The flaws include an authentication bypass issue with a 9.8 CVE score (CVE-2023-49105) and a highly dangerous flaw related to the oauth2 app (CVE-2023-49104).

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : TechSpot – https://www.techspot.com/news/100994-critical-vulnerability-owncloud-servers-exploited-en-masse.html

Tags: criticaltechnologyvulnerability
Previous Post

Where to watch Christmas at Graceland holiday special

Next Post

Court mandates Epic and Google to settlement talks before concluding antitrust lawsuit

New Research Shows Changing Winters Will Hit Northern Lakes the Hardest – Hometown Focus

New Research Reveals How Changing Winters Threaten Northern Lakes the Most

October 25, 2025
Scientists reversed brain aging and memory loss in mice – Science Daily

Breakthrough Discovery: Scientists Reverse Brain Aging and Restore Memory in Mice

October 25, 2025
It’s alive! Spooky science activities to take place Oct. 25-26 at Discovery Playhouse – KFVS12

It’s Alive! Exciting Spooky Science Activities Coming to Discovery Playhouse Oct. 25-26

October 25, 2025
Buying property in Israel: how to choose between lifestyle and investment goals – Ynetnews

Buying Property in Israel: Balancing Your Lifestyle Dreams with Smart Investment Choices

October 25, 2025
Comments to EU Regarding the Draft Revised Technology Transfer Block Exemption Regulation and Technology Transfer Guidelines – Information Technology and Innovation Foundation

Have Your Say: Share Your Thoughts on the Draft Revised Technology Transfer Block Exemption Regulation and Guidelines

October 25, 2025
The NBA Made a Big Bet on Sports Gambling—and It Just Blew Up – The Wall Street Journal

The NBA Made a Big Bet on Sports Gambling—and It Just Blew Up – The Wall Street Journal

October 25, 2025
The $500m slugger who is taking Canada to the World Series – BBC

The $500 Million Slugger Powering Canada’s Journey to World Series Glory

October 25, 2025
Russian Central Bank Cuts Key Rate to 16.5% as Economy Slows – The Moscow Times

Russian Central Bank Cuts Key Rate to 16.5% in Response to Economic Slowdown

October 25, 2025
General Hospital’s Rena Sofer Exits as Lois — But the Door Isn’t Closed – Yahoo

General Hospital’s Rena Sofer Exits as Lois — But the Door Isn’t Closed – Yahoo

October 25, 2025
Health Department Encourages Residents to Take Steps to Prevent Respiratory Viruses – | Larimer County (.gov)

Stay Healthy This Season: Must-Know Tips to Shield Yourself from Respiratory Viruses

October 25, 2025

Categories

Archives

October 2025
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Sep    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (886)
  • Economy (907)
  • Entertainment (21,778)
  • General (17,801)
  • Health (9,948)
  • Lifestyle (920)
  • News (22,149)
  • People (908)
  • Politics (917)
  • Science (16,118)
  • Sports (21,407)
  • Technology (15,887)
  • World (890)

Recent News

New Research Shows Changing Winters Will Hit Northern Lakes the Hardest – Hometown Focus

New Research Reveals How Changing Winters Threaten Northern Lakes the Most

October 25, 2025
Scientists reversed brain aging and memory loss in mice – Science Daily

Breakthrough Discovery: Scientists Reverse Brain Aging and Restore Memory in Mice

October 25, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version