First published: Tue Nov 21 2023(Updated: )
An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect-url that bypasses validation, and consequently allows an attacker to redirect callbacks to a Top Level Domain controlled by the attacker.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ownCloud oauth2 | <0.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-49104.
The severity of CVE-2023-49104 is high with a severity value of 8.7.
CVE-2023-49104 affects ownCloud oauth2 with versions up to but excluding 0.6.1.
An attacker can bypass validation and redirect callbacks to a Top Level Domain controlled by them.
To fix CVE-2023-49104, upgrade to version 0.6.1 or later of ownCloud oauth2.