CVE List

CVE-2020-22784

Critical 7.5

In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names.

Published April 28, 2021.

Affected software

Get alerts for Etherpad Ueberdb

Reference links