CVE-2020-22781: SQL Injection
Published Apr 28, 2021
·Updated
In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash the instance).
Affected Software
1 affected component
Etherpad Etherpad<1.8.3
Event History
Apr 28, 2021
CVE Published
via MITRE·08:23 PM
Data Sourced
via MITRE·08:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-22781?
CVE-2020-22781 has been rated as a high severity vulnerability due to its ability to crash the Etherpad instance.
2
How do I fix CVE-2020-22781?
To fix CVE-2020-22781, upgrade Etherpad to version 1.8.3 or later.
3
What type of vulnerability is CVE-2020-22781?
CVE-2020-22781 is a denial of service vulnerability affecting Etherpad versions before 1.8.3.
4
What happens if CVE-2020-22781 is exploited?
Exploiting CVE-2020-22781 can lead to an unhandled exception that crashes the Etherpad instance.
5
Which versions of Etherpad are affected by CVE-2020-22781?
CVE-2020-22781 affects all Etherpad versions prior to 1.8.3.