{"id":"CVE-2023-49105","aliases":[],"url":"https://o3.security/vulnerability/CVE-2023-49105","summary":null,"details":"An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.","published":"2023-11-21T00:00:00Z","modified":"2026-08-12T03:51:32.360657147Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://owncloud.org/security"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49105.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49105"},{"type":"ADVISORY","url":"https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:32.360657147Z"}}