LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-49103: ownCloud graphapi Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 30, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 21, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-49103 to its Known Exploited Vulnerabilities catalog on Nov 30, 2023, with a federal patch deadline of Dec 21, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials.

CVE-2023-49103 is an information disclosure vulnerability in the ownCloud graphapi component. It allows exposure of sensitive data that phpinfo() stores, accessed through GetPhpInfo.php, and that data can include administrative credentials. For IT and security teams running ownCloud, this matters because credential leakage can enable further unauthorized access to file-sharing environments that often hold business-critical data.

Public detail is limited to the CISA description of the issue; confirm exact impact, affected configurations, and fixes against the vendor advisory before acting.

How it works

The flaw is an information disclosure issue in ownCloud graphapi. An attacker who can reach the GetPhpInfo.php endpoint can obtain the output of phpinfo(), which routinely surfaces environment details, configuration values, and other sensitive material that may include administrative credentials. No specific CWE is listed in the provided record, so treat this as a classic sensitive-data exposure through an unintended diagnostic or debug interface. Exact request mechanics, authentication requirements, or remote reachability are not detailed here; confirm those against the vendor advisory rather than assuming unauthenticated remote access.

Am I affected? How to find it in your systems

ownCloud is commonly deployed as a self-hosted file-sync and collaboration platform, often on Linux servers with PHP and web-server front ends (Apache or nginx). The graphapi component is part of that stack. Inventory steps:

If the product is no longer supported or mitigations are unavailable, CISA guidance is to discontinue use.

How to remediate

Patch first. Apply the vendor update or mitigation instructions named in the official ownCloud advisory for CVE-2023-49103. After applying the update:

If the vendor provides configuration changes instead of a binary patch, implement those exactly as documented.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These steps lower risk but do not replace the vendor fix. Discontinue use if no mitigations are available.

If your data may have been exposed

Actively exploited information-disclosure flaws can lead to credential theft and subsequent breaches of the file-sharing environment. Review access logs for signs of GetPhpInfo.php access, assume any credentials visible in phpinfo() output are compromised, and rotate them. Monitor for lateral movement or unusual file access. Readers can run a free exposure scan of their email addresses against known breach data sets to check whether related accounts appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedownCloud · ownCloud graphapi
Added to CISA KEVNov 30, 2023
Federal patch deadlineDec 21, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities