CVE-2020-22785: High severity etherpad ueberdb vulnerability
Published Apr 28, 2021
·Updated
Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rate limiting and missing ownership check.
Affected Software
1 affected component
Etherpad Etherpad<1.8.3
Event History
Apr 28, 2021
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-22785?
CVE-2020-22785 has a moderate severity level due to its potential for causing a denial of service.
2
How do I fix CVE-2020-22785?
To fix CVE-2020-22785, upgrade Etherpad to version 1.8.3 or later.
3
What systems are affected by CVE-2020-22785?
CVE-2020-22785 affects Etherpad versions prior to 1.8.3.
4
What type of attack does CVE-2020-22785 enable?
CVE-2020-22785 enables denial of service attacks through aggressive exploitation of random pad import endpoints.
5
Is there a workaround for CVE-2020-22785?
Currently, there is no official workaround for CVE-2020-22785 other than upgrading to the patched version.