惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
阮一峰的网络日志
阮一峰的网络日志
有赞技术团队
有赞技术团队
小众软件
小众软件
P
Proofpoint News Feed
P
Proofpoint News Feed
Apple Machine Learning Research
Apple Machine Learning Research
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
The Last Watchdog
The Last Watchdog
O
OpenAI News
Security Latest
Security Latest
博客园 - Franky
Forbes - Security
Forbes - Security
N
Netflix TechBlog - Medium
H
Hacker News: Front Page
Cloudbric
Cloudbric
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Hugging Face - Blog
Hugging Face - Blog
Microsoft Security Blog
Microsoft Security Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
S
Security Affairs
Recent Announcements
Recent Announcements
The GitHub Blog
The GitHub Blog
S
Schneier on Security
MongoDB | Blog
MongoDB | Blog
WordPress大学
WordPress大学
Last Week in AI
Last Week in AI
博客园 - 【当耐特】
Attack and Defense Labs
Attack and Defense Labs
C
Cyber Attacks, Cyber Crime and Cyber Security
F
Fortinet All Blogs
Webroot Blog
Webroot Blog
S
Secure Thoughts
Spread Privacy
Spread Privacy
Blog — PlanetScale
Blog — PlanetScale
T
Troy Hunt's Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
V2EX
Security Archives - TechRepublic
Security Archives - TechRepublic
P
Privacy & Cybersecurity Law Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Simon Willison's Weblog
Simon Willison's Weblog
C
Check Point Blog
L
LINUX DO - 最新话题
NISL@THU
NISL@THU
博客园_首页
罗磊的独立博客
A
Arctic Wolf
U
Unit 42

OpenCloud: Exzellentes Filesharing: Sichere und skalierbare Cloud-Lösungen

Support OpenCloud via GitHub Sponsors OpenCloud Production Release: Digital collaboration with structured content based on Markdown The OpenCloud Production Release enhances digital collaboration with structured, Markdown-based content OpenCloud at the IT Sovereignty and OSS Day II in Nuremberg OpenCloud at the GITEX 2026 OpenCloud and FUAGO: More flexibility for sovereign file collaboration OpenCloud and esatus show EUDI wallet login in OpenCloud New rolling release: Breadcrumb navigation and search shortcut OpenCloud at the Rack & Stack 2026 Rolling Release Feature Highlight: Favourites in OpenCloud OpenCloud and real-cis: Strengthening sovereign IT infrastructures OpenCloud at the Chemnitz Linux Days 2026 OpenCloud at the CS3 Conference 2026 in Oslo OpenCloud at the Digitaler Staat 2026 congress in Berlin OpenCloud and net42: Partnership for sovereign IT infrastructures Vulnerabilities in the code: Why transparency and enterprise licences provide security Rolling release feature highlight: Faster photo viewing in the Preview app OpenCloud and CAIRO: IT security and digital sovereignty We are at the FOSDEM 2026 in Brussels OpenCloud at the Univention Summit 2026 OpenCloud Production Release brings file management to provider level: true multi-tenancy and high availability OpenCloud Production Release: From Multi-tenancy to Helm Charts OpenCloud and Indeno: More performance through collaboration
OpenCloud developers find high severity vulnerability - patch available
Anne Gossing · 2026-02-05 · via OpenCloud: Exzellentes Filesharing: Sichere und skalierbare Cloud-Lösungen

05.02.2026 - Updates

Our security team at OpenCloud has discovered a vulnerability in Public Links and rated it CVSS 8.2 (High). This vulnerability was originally created in the code of ownCloud (Kiteworks) and was also included in the OCIS fork of OpenCloud.

Vulnerability discovered

As is customary in the open source environment, the team informed both CERN and ownCloud (Kiteworks) in advance, whose software is based in part on the same codebase as OpenCloud. This ensured that all affected parties were able to check their codebase and protect customer installations, such as the BayernCloud Schule (ByCS).

Today we are publicising this vulnerability and providing an important patch for OpenCloud.

We handled the discovery in accordance with responsible disclosure principles. Our customers with an Enterprise licence were protected at all times via their subscription. We ensure that every customer is informed and receives the necessary support for rapid protection and updates. Our support team is still available to answer any questions our customers may have.

Affected versions

CVE-2026-23989

All OpenCloud instances below version 4.0.3 and all instances below 5.0.2 are affected. The patched versions are 4.0.3 and 5.0.2.

Security patch available

With the release of the vulnerability today, we are also publishing the patch publicly online. We recommend that you schedule and install the update very immediately to ensure the security of your data.

You can find the current patch version in the advisory

Immediate action until the patch is applied

  • Disable the public links on your instances if you cannot apply the patch immediately.
  • Make the following configuration:
    • Configuration customisation
      • Docker Compose: Edit the docker-compose.yml and set GATEWAY_STORAGE_PUBLIC_LINK_ENDPOINT="" (empty string value) in the "environment" section of the "opencloud" container.
      • Kubernetes: Edit the deployment opencloud-api and set name: GATEWAY_STORAGE_PUBLIC_LINK_ENDPOINT
        value: "" (empty string)
        in the "env" section of the "spec" of the container "api".
  • Verify that the mitigation is active and perform the following test:
    • Create a public link as a test
    • Open the link in a private (no active login) browser tab.
    • You will see an error page with the message "File not found"
  • Inform your IT team and relevant stakeholders

Patch installation

  • The public patch version is available as of today, 05.02.2026 (can be found in the advisory)
  • Plan your maintenance window, ensure your backups, prepare your test/staging environment
  • Download the patch version 4.0.3
  • Test the patch in your test environment
  • Run the patch installation in the production environment
  • Verify the successful installation
  • Remove the temporary security configuration
  • if necessary. the temporary security configuration

For more information, please also take a look at our release notes and read our blog "Vulnerabilities in the code: Why transparency and enterprise licences provide security"

More news