Vulnerability record · CVE-2023-49103 · published 21 November 2023
CVE-2023-49103: ownCloud graphapi phpinfo endpoint leaks environment credentials
Owncloud · Graph Api
The ownCloud graphapi app bundles a third-party GetPhpInfo.php library that exposes a URL returning full PHP environment output (phpinfo). In containerized deployments those environment variables can include the ownCloud admin password, mail server credentials and license key. Disabling the graphapi app alone does not remove the exposure, and the leak also reveals other sensitive system configuration.
Description
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system. Therefore, even if ownCloud is not running in a containerized environment, this vulnerability should still be a cause for concern. Note that Docker containers from before February 2023 are not vulnerable to the credential disclosure.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityIt is in CISA KEV with a near-top EPSS score and allows unauthenticated disclosure of administrative credentials.
What it is
The ownCloud graphapi app bundles a third-party GetPhpInfo.php library that exposes a URL returning full PHP environment output (phpinfo). In containerized deployments those environment variables can include the ownCloud admin password, mail server credentials and license key. Disabling the graphapi app alone does not remove the exposure, and the leak also reveals other sensitive system configuration.
Impact
An unauthenticated attacker who reaches the endpoint gains credentials and configuration data that can enable direct administrative access to ownCloud and lateral movement to connected mail or infrastructure services.
Attack surface
Reachable over the network via a URL served by the graphapi app; the CVSS vector shows no privileges or user interaction required. Any deployment exposing the affected graphapi versions is in scope, with containerized installs at highest risk.
Exploitation
Listed in CISA KEV with a 2023-12-21 remediation due date, and EPSS is 0.784 (99.6th percentile), indicating active exploitation and very high likelihood. No ransomware campaign use is recorded.
What to do
- Upgrade ownCloud graphapi to 0.2.1 or 0.3.1 (or later) as directed by the vendor advisory.
- If patching is not immediately possible, block external access to the GetPhpInfo.php path and the graphapi app at the web server or reverse proxy.
- Rotate all credentials that may have been exposed through environment variables, including the ownCloud admin password, mail server credentials and license key.
- Review container environment variable handling and move secrets out of plain environment variables where feasible.
- Do not rely on disabling the graphapi app alone, since the vendor states this does not eliminate the vulnerability.
Detection
- Search web and proxy logs for requests to GetPhpInfo.php or phpinfo-related paths under the graphapi app.
- Alert on unexpected access to graphapi endpoints from external or unfamiliar source IPs.
- Monitor for authentication attempts or logins using the ownCloud admin account from new locations after exposure.
- Audit container environment variables and configuration for secrets that would be disclosed by phpinfo output.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-49103 to the Known Exploited Vulnerabilities catalog on 30 November 2023 as "ownCloud graphapi Information Disclosure Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 21 December 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-49103 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2023-49103), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.