A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.
https://nextcloud.com/security/advisory/?id=NC-SA-2020-033
https://hackerone.com/reports/922470
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00019.html