A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules. https://hackerone.com/reports/1018146 https://nextcloud.com/security/advisory/?id=NC-SA-2021-001
Created nextcloud tracking bugs for this issue: Affects: fedora-all [bug 1921306]
Can whoever manages these monitoring scripts please make them check if any affected versions are actually in the repositories?
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.