CVE-2020-8293: Input Validation
A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8293?
CVE-2020-8293 is classified as a medium severity vulnerability due to its potential for causing a denial of service.
How do I fix CVE-2020-8293?
To fix CVE-2020-8293, upgrade your Nextcloud Server to version 20.0.2 or higher, 19.0.5 or higher, or 18.0.11 or higher.
Which versions of Nextcloud Server are affected by CVE-2020-8293?
CVE-2020-8293 affects Nextcloud Server versions prior to 20.0.2, 19.0.5, and 18.0.11.
What risks are associated with CVE-2020-8293?
CVE-2020-8293 poses risks of excessive resource consumption and potential denial of service due to unlimited data storage in workflow rules.
Is there a workaround for CVE-2020-8293?
There are no official workarounds for CVE-2020-8293; upgrading to the patched versions is the recommended solution.