Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-22785

Опубликовано: 28 апр. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rate limiting and missing ownership check.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:etherpad:etherpad:*:*:*:*:*:*:*:*
Версия до 1.8.3 (исключая)

EPSS

Процентиль: 51%
0.0028
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
debian
почти 5 лет назад

Etherpad < 1.8.3 is affected by a missing lock check which could cause ...

github
больше 3 лет назад

Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rate limiting and missing ownership check.

EPSS

Процентиль: 51%
0.0028
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-770