Ratelimits do not apply to OCS DataResponse

Disclosed: 2021-08-11 09:14:01 By lukasreschkenc To nextcloud
None
Vulnerability Details
Using `$response->throttle()` on a DataResponse doesn't work as it is being transformed by BaseResponse into a OCS response. This response does not propagate any throttled setting. ## Impact Ratelimits on OCS DataResponse not functional.
Actions
View on HackerOne
Report Stats
  • Report ID: 1214158
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report