CVE-2020-22784: High severity etherpad vulnerability
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-22784?
CVE-2020-22784 has a medium severity as it can lead to unauthorized access due to access control bypass.
How do I fix CVE-2020-22784?
To mitigate CVE-2020-22784, upgrade Etherpad UeberDB to version 0.4.4 or later where the vulnerability is addressed.
What systems are affected by CVE-2020-22784?
CVE-2020-22784 affects Etherpad UeberDB versions prior to 0.4.4 when using the MySQL connector.
What type of vulnerability is CVE-2020-22784?
CVE-2020-22784 is an access control vulnerability that allows key name comparisons to be bypassed.
Can CVE-2020-22784 be exploited remotely?
Yes, CVE-2020-22784 can potentially be exploited remotely if the vulnerable software is exposed to untrusted users.