Vulnerability Description
Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rate limiting and missing ownership check.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Etherpad | Etherpad | < 1.8.3 |
Related Weaknesses (CWE)
References
- https://github.com/ether/etherpad-lite/pull/3833ExploitIssue TrackingThird Party Advisory
- https://github.com/ether/etherpad-lite/pull/3833ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2020-22785?
CVE-2020-22785 is a vulnerability with a CVSS score of 7.5 (HIGH). Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rat...
How severe is CVE-2020-22785?
CVE-2020-22785 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-22785?
Check the references section above for vendor advisories and patch information. Affected products include: Etherpad Etherpad.