← Back

CVE-2020-8293

nvd nist
Published: Jan 26, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.

Affected (3)

1 product
Nextcloud Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
Before 18.0.11
From 19.0.0 to 19.0.5
From 20.0.0 to 20.0.2

References (4)

Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory

Timeline

No history available yet.