ownCloud in KEV: a WebDAV authentication bypass through pre-signed URLs
CISA added CVE-2023-49105 to the Known Exploited Vulnerabilities catalog: an authentication bypass in the ownCloud WebDAV API involving pre-signed URLs. Here is how to check whether your own perimeter exposes an affected instance, and where the patching chain usually breaks.
Read the article →