CVE-2023-49103 Details
Description
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system. Therefore, even if ownCloud is not running in a containerized environment, this vulnerability should still be a cause for concern. Note that Docker containers from before February 2023 are not vulnerable to the credential disclosure.
A vulnerability exists in the ownCloud GraphAPI application, specifically in versions 0.2.x prior to 0.2.1 and 0.3.x prior to 0.3.1. The issue arises from the app's reliance on a third-party library, GetPhpInfo.php, which, when accessed, discloses PHP environment configuration details through the phpinfo() function. This information includes webserver environment variables that, in containerized deployments, may contain sensitive data such as the ownCloud admin password, mail server credentials, and license key. The vulnerability persists even when the GraphAPI app is disabled, and while Docker containers deployed before February 2023 are not affected, the issue remains a concern for ownCloud installations outside of a containerized environment.
Users are advised to delete the file 'GetPhpInfo.php' from the GraphAPI application's vendor directory and to change any exposed secrets such as the ownCloud admin password, mail server credentials, database credentials, and S3 access keys.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| ownCloud graphapi Information Disclosure Vulnerability | Nov 30, 2023 | Dec 21, 2023 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| owncloud graph api | 0.2.0 0.3.0 |
CPE
Remediation
| |
Change History
18 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Oct 31, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Dec 20, 2024 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Sep 5, 2024 | Modified Analysis | [email protected] |
| Sep 4, 2024 | CVE Modified | CISA-ADP |
| Jun 26, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 5, 2023 | CVE Modified | [email protected] |
| Dec 5, 2023 | CVE Source Update | [email protected] |
| Dec 5, 2023 | CVE Source Update | [email protected] |
| Dec 5, 2023 | CVE Modified | [email protected] |
| Dec 2, 2023 | Initial Analysis | [email protected] |
| Nov 21, 2023 | New CVE Received | [email protected] |