Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7wwq-q495-rfg3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rate limiting and missing ownership check.

Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rate limiting and missing ownership check.

EPSS

Процентиль: 51%
0.0028
Низкий

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
nvd
почти 5 лет назад

Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rate limiting and missing ownership check.

CVSS3: 7.5
debian
почти 5 лет назад

Etherpad < 1.8.3 is affected by a missing lock check which could cause ...

EPSS

Процентиль: 51%
0.0028
Низкий

Дефекты

CWE-770