A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.
References
| Link | Resource |
|---|---|
| https://hackerone.com/reports/1018146 | Third Party Advisory |
| https://nextcloud.com/security/advisory/?id=NC-SA-2021-001 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-01-26 18:16
Updated : 2021-02-02 17:45
NVD link : CVE-2020-8293
Mitre link : CVE-2020-8293
JSON object : View
Products Affected
nextcloud
- nextcloud
CWE
CWE-400
Uncontrolled Resource Consumption
