PT-2021-23932 · Nodebb · Nodebb

Julianlam

·

Published

2021-11-29

·

Updated

2022-10-27

·

CVE-2021-43786

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Nodebb versions prior to 1.18.5
Description: The issue is related to incorrect logic in the token verification step, which unintentionally allowed master token access to the API.
Recommendations: For versions prior to 1.18.5, upgrade to version 1.18.5 or later as soon as possible. As a temporary workaround, consider cherry-picking commit hash 04dab1d550cdebf4c1567bca9a51f8b9ca48a500 to receive the patch in lieu of a full upgrade.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2021-43786
GHSA-HF2M-J98R-4FQW

Affected Products

Nodebb