HTTP: ownCloud Graph API information disclosure

This signature detects attempts to exploit a known vulnerability against ownCloud Graph API . A successful attack can lead to sensitive information disclosure.

Extended Description

An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system. Therefore, even if ownCloud is not running in a containerized environment, this vulnerability should still be a cause for concern. Note that Docker containers from before February 2023 are not vulnerable to the credential disclosure.

Affected Products

Owncloud graph_api

References

CVE: CVE-2023-49103

Short Name
HTTP:CTS:OWNCLOUD-API-INFODIS
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
API CVE-2023-49103 Graph disclosure information ownCloud
Release Date
05/05/2025
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3805
False Positive
Unknown
Vendors

Owncloud

Found a potential security threat?