Description
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-15541 | In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T14:51:11.171Z
Reserved: 2020-08-13T00:00:00.000Z
Link: CVE-2020-22784
No data.
Status : Modified
Published: 2021-04-28T21:15:08.683
Modified: 2024-11-21T05:13:24.800
Link: CVE-2020-22784
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD