First published: Mon Oct 05 2020(Updated: )
A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Preferred Providers | =1.7.0 | |
openSUSE Backports SLE | =15.0-sp1 | |
openSUSE Backports SLE | =15.0-sp2 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8228 is a vulnerability in the Preferred Providers app 1.7.0 that allowed an attacker to set the password an uncontrolled amount of times due to a missing rate limit.
The severity of CVE-2020-8228 is medium with a severity value of 5.3.
Nextcloud Preferred Providers 1.7.0, openSUSE Backports SLE 15.0-sp1 and 15.0-sp2, openSUSE Leap 15.1 and 15.2 are affected by CVE-2020-8228.
An attacker can exploit CVE-2020-8228 by abusing the missing rate limit in the Preferred Providers app 1.7.0 to repeatedly set the password.
More information about CVE-2020-8228 can be found in the references provided: http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00019.html, https://hackerone.com/reports/922470, and https://nextcloud.com/security/advisory/?id=NC-SA-2020-033.