VDB
CVE-2020-8293
CVE-2020-8293
PUBLISHED
CVSS 6.5 MEDIUM
A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.
EPSS 0.63% · 70.6th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.63%
70.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| nextcloud | nextcloud_server | 19.0.0, 0, 20.0.0 |
| n/a | Nextcloud Server | 20.0.2 |
Exploit Intelligence
- https://hackerone.com/reports/1018146 (nist-nvd)
- Potential DDoS when posting long data into workflow validation rules (hackerone)
- Potential DDoS when posting long data into workflow validation rules (hackerone)
- Potential DDoS when posting long data into workflow validation rules (hackerone)
- https://nextcloud.com/security/advisory/?id=NC-SA-2021-001 (circl)
Timeline
- CVE Published
- Jan 21, 2021 PoC Published
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Mar 11, 2023 EPSS Score