CVE-2022-43679: Medium severity ownCloud ownCloud vulnerability
Published Nov 10, 2022
·Updated
The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusteddomains config useless. This could be abused to spoof the URL in password-reset e-mail messages.
Affected Software
1 affected component
ownCloud ownCloud<=10.11.0
Event History
Nov 10, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this misconfiguration in ownCloud Server Docker image?
The vulnerability ID for this misconfiguration in ownCloud Server Docker image is CVE-2022-43679.
2
What is the impact of this vulnerability in the ownCloud Server Docker image?
This vulnerability in the ownCloud Server Docker image allows an attacker to spoof the URL in password-reset email messages.
3
What is the severity rating of CVE-2022-43679?
CVE-2022-43679 has a severity rating of medium (5.3).
4
How can an attacker exploit this vulnerability in the ownCloud Server Docker image?
An attacker can exploit this vulnerability by abusing the misconfiguration to spoof the URL in password-reset email messages.
5
Is there a fix available for CVE-2022-43679?
Yes, you can fix this vulnerability by updating the ownCloud Server Docker image to a version higher than 10.11.0.