Описание
Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally allowed master token access to the API. The vulnerability has been patch as of v1.18.5. Users are advised to upgrade as soon as possible.
Ссылки
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.15.0 (включая) до 1.18.4 (включая)
cpe:2.3:a:nodebb:nodebb:*:*:*:*:*:*:*:*
EPSS
Процентиль: 64%
0.00475
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 9.8
github
около 4 лет назад
API token verification can be bypassed in NodeBB
EPSS
Процентиль: 64%
0.00475
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-287