ZeroHour

CVE-2020-22785

PoC
CVSS 3.1
7.5 high
EPSS
1%p63
Published
()
Modified
Description

Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rate limiting and missing ownership check.

Vendors
etherpad
Products
etherpad
Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.