PT-2021-10791 · Unknown · Etherpad Ueberdb

Published

2021-04-28

·

Updated

2022-07-12

·

CVE-2020-22784

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Etherpad UeberDB versions prior to 0.4.4
Description The issue allows bypassing access controls enforced on key names when retrieving database records using UeberDB's MySQL connector. This is due to MySQL omitting trailing spaces on char / varchar columns during comparisons.
Recommendations For versions prior to 0.4.4, update to version 0.4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive key names to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-22784

Affected Products

Etherpad Ueberdb