The 3 vulnerabilities are:
- WebDAV Api Authentication Bypass using Pre-Signed URLs - CWE ID: CWE-665
- Subdomain Validation Bypass (oAuth2) - CWE ID: CWE-284
- CVE-2023-49103
The 3 vulnerabilities are:
No
(10 characters)
please check this repository as reliable source Security Overview · nextcloud/security-advisories · GitHub
See also our official statement on the subject - Security statement on ownCloud breach - Nextcloud