We found results for “”
CVE-2020-8293
Good to know:
Date: January 26, 2021
A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Uncontrolled Resource Consumption
CWE-400Top Fix
Upgrade Version
Upgrade to version nextcloud/ocp - v19.0.0-beta1;nextcloud/ocp - v19.0.8;nextcloud/ocp - v20.0.2;nextcloud/ocp - dev-stable20;christophwurst/nextcloud - v14.0.2;christophwurst/nextcloud - 14.0.0-beta4;christophwurst/nextcloud - v14.0.1-RC1;christophwurst/nextcloud - v15.0.3;christophwurst/nextcloud - 16.0.0-beta3;christophwurst/nextcloud - v14.0.1;christophwurst/nextcloud - v19.0.8;christophwurst/nextcloud - v16.0.0;christophwurst/nextcloud - dev-stable20;christophwurst/nextcloud - v20.0.2;christophwurst/nextcloud - v12.0.0;christophwurst/nextcloud - v15.0.0-RC2;christophwurst/nextcloud - v14.0.4-RC1;christophwurst/nextcloud - v16.0.0-beta1;christophwurst/nextcloud - 14.0.0-RC1;christophwurst/nextcloud - v13.0.8-RC2;christophwurst/nextcloud - v15.0.0;christophwurst/nextcloud - v16.0.0-RC1;christophwurst/nextcloud - v19.0.0-beta1
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | HIGH |
CVSS v2
| Base Score: |
|
|---|---|
| Access Vector (AV): | NETWORK |
| Access Complexity (AC): | LOW |
| Authentication (AU): | SINGLE |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | PARTIAL |
| Additional information: |
Vulnerabilities
Projects
Contact Us


