Misconfiguration in ownCloud Server Docker Image Compromises URL Spoofing
CVE-2022-43679
5.3MEDIUM
What is CVE-2022-43679?
A misconfiguration in the Docker image of ownCloud Server version 10.11 allows for the trusted_domains configuration to be bypassed. This vulnerability could be exploited to manipulate the URL in password-reset emails, potentially misleading users into entering their credentials on fraudulent websites.