CVE-2020-22784: Etherpad Ueberdb

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names.

Affected products

  • Etherpad Ueberdb: before 1.4.8 (fixed in 1.4.8)

Published 2021-04-28. Last modified 2026-06-17.