
Cloud Vulnerability DB
A community-led vulnerabilities database
The Docker image of ownCloud Server through version 10.11 contains a critical misconfiguration vulnerability (CVE-2022-43679) that was disclosed on November 10, 2022. This vulnerability renders the trusted_domains configuration ineffective, affecting the security of ownCloud Server deployments using Docker containers (NVD, CVE).
The vulnerability has been assigned a CVSS v3.1 base score of 5.3 (Medium severity). The issue specifically relates to a misconfiguration in the Docker container that invalidates the trusted_domains configuration setting, which is designed to control domain-based access to the ownCloud instance (NVD).
The primary impact of this vulnerability is that it could be exploited to spoof URLs in password-reset email messages. This could potentially lead to phishing attacks where users are directed to malicious sites through seemingly legitimate password reset emails from their ownCloud instance (NVD).
The vulnerability affects Docker deployments of ownCloud Server through version 10.11. To exploit this vulnerability, an attacker would need to leverage the misconfigured trusted_domains setting to manipulate password reset email URLs (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."