meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, November 28th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 28 November 2023

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. OwnCloud Exploited; Fingerprint Reader Weakness

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, November 28, 2023 edition of the Sandcent Storm Center's Stormcast.

0:08.7

My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:14.9

One issue I probably should have covered yesterday, but while I sort of ran out of time, is three vulnerabilities in OnCloud.

0:22.6

OwnCloud is an open source file sharing system. It does have sort of a commercial component

0:29.1

to it. And OnCloud did on November 21st, so just last week, release an update that fixes three critical vulnerabilities, one of which

0:41.1

we already see being exploited in our sensors.

0:45.8

The one that's already exploited is also the one that's the most severe of the vulnerabilities.

0:51.7

That's CVE 2023-49-3. CVSS score of 10 and it does, yes, allow

1:01.1

arbitrary code execution as administrator appears to be most critical or most severe if the

1:09.8

own cloud install is running inside a container.

1:14.4

The problem here is that the Graph API library that is installed with OnGlaude does provide some

1:22.7

test scripts that remained on the system, and one of them gets you access to PHP info.

1:30.5

If you're familiar with PHP, PHP info is often used for debugging.

1:36.0

It's a command that sort of dumps the entire system configuration, including in this case

1:41.3

usernames and passwords for administrator,

1:45.0

also things like API keys,

1:47.0

in particular if you're connecting to something like S3 with OnCloud

1:51.4

and the mail server credentials and the like.

1:55.4

The second vulnerability CVE 20203-49105

2:00.8

does allow the arbitrary modification and deletion of files if any of your users

2:06.5

has no signing key configured.

2:09.6

And that's the default if you just set up a new user.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.