Vulnerabilities > CVE-2020-8228 - Improper Restriction of Excessive Authentication Attempts vulnerability in multiple products
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
LOW Summary
A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
Application | 2 | |
OS | 2 |
Common Weakness Enumeration (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00019.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00019.html
- https://hackerone.com/reports/922470
- https://hackerone.com/reports/922470
- https://nextcloud.com/security/advisory/?id=NC-SA-2020-033
- https://nextcloud.com/security/advisory/?id=NC-SA-2020-033