CVE-2020-8293

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-8293
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-8293.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-8293
Related
Published
2021-01-26T18:16:08Z
Modified
2025-01-14T08:57:15.206723Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.

References

Affected packages

Git / github.com/nextcloud/server

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/server
Events

Affected versions

v19.*

v19.0.0
v19.0.1
v19.0.1RC1
v19.0.2
v19.0.2RC1
v19.0.2RC2
v19.0.3
v19.0.3RC1
v19.0.4
v19.0.40RC1
v19.0.4RC2
v19.0.5RC1
v19.0.5RC2