Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rf3g-v8p5-p675

Опубликовано: 05 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.4

Описание

NodeBB vulnerable to account takeover via prototype vulnerability

Impact

Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts.

Patches

Patched in 2.6.1

Workarounds

Site maintainers can cherry-pick https://github.com/NodeBB/NodeBB/commit/48d143921753914da45926cca6370a92ed0c46b8 into their codebase to patch the exploit.

For more information

If you have any questions or comments about this advisory:

Discuss it on our community forum Email us at support@nodebb.org

Пакеты

Наименование

nodebb

npm
Затронутые версииВерсия исправления

< 2.6.1

2.6.1

EPSS

Процентиль: 98%
0.56836
Средний

9.4 Critical

CVSS3

Дефекты

CWE-665

Связанные уязвимости

CVSS3: 9.4
nvd
около 3 лет назад

NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1. Users are advised to upgrade. Users unable to upgrade may cherry-pick commit `48d143921753914da45926cca6370a92ed0c46b8` into their codebase to patch the exploit.

EPSS

Процентиль: 98%
0.56836
Средний

9.4 Critical

CVSS3

Дефекты

CWE-665