A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.
References
Link | Resource |
---|---|
https://hackerone.com/reports/1018146 | Third Party Advisory |
https://nextcloud.com/security/advisory/?id=NC-SA-2021-001 | Broken Link Vendor Advisory |
https://hackerone.com/reports/1018146 | Third Party Advisory |
https://nextcloud.com/security/advisory/?id=NC-SA-2021-001 | Broken Link Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:38
Type | Values Removed | Values Added |
---|---|---|
References | () https://hackerone.com/reports/1018146 - Third Party Advisory | |
References | () https://nextcloud.com/security/advisory/?id=NC-SA-2021-001 - Broken Link, Vendor Advisory |
Information
Published : 2021-01-26 18:16
Updated : 2024-11-21 05:38
NVD link : CVE-2020-8293
Mitre link : CVE-2020-8293
CVE.ORG link : CVE-2020-8293
JSON object : View
Products Affected
nextcloud
- nextcloud_server
CWE
CWE-400
Uncontrolled Resource Consumption