PT-2022-5543 · Owncloud · Owncloud Server

Published

2022-10-20

·

Updated

2025-05-01

·

CVE-2022-43679

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions ownCloud Server versions prior to 10.11
Description The issue is related to a misconfiguration in the ownCloud Server Docker image that affects the trusted domains config, making it useless. This could be exploited to spoof the URL in password-reset email messages. The vulnerability is also related to errors in handling the OWNCLOUD DOMAIN variable, which could allow a remote attacker to conduct spoofing attacks by sending a specially crafted email message.
Recommendations For ownCloud Server versions prior to 10.11, update to a version that fixes the misconfiguration and OWNCLOUD DOMAIN variable handling issues to prevent spoofing attacks. As a temporary workaround, consider restricting access to the password-reset functionality until a patch is available.

Fix

Improper Access Control

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-06872
CVE-2022-43679

Affected Products

Owncloud Server