PT-2022-5543 · Owncloud · Owncloud Server
Published
2022-10-20
·
Updated
2025-05-01
·
CVE-2022-43679
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ownCloud Server versions prior to 10.11
Description
The issue is related to a misconfiguration in the ownCloud Server Docker image that affects the trusted domains config, making it useless. This could be exploited to spoof the URL in password-reset email messages. The vulnerability is also related to errors in handling the OWNCLOUD DOMAIN variable, which could allow a remote attacker to conduct spoofing attacks by sending a specially crafted email message.
Recommendations
For ownCloud Server versions prior to 10.11, update to a version that fixes the misconfiguration and OWNCLOUD DOMAIN variable handling issues to prevent spoofing attacks. As a temporary workaround, consider restricting access to the password-reset functionality until a patch is available.
Fix
Improper Access Control
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Owncloud Server