PT-2023-22800 · Nodebb · Nodebb

Creastery

+1

·

Published

2023-09-28

·

Updated

2023-10-02

·

CVE-2023-30591

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NodeBB versions <= 2.8.10
Description The issue allows unauthenticated attackers to trigger a crash in NodeBB when invoking eventName.startsWith() or eventName.toString(), while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name respectively.
Recommendations For NodeBB versions <= 2.8.10, update to a version greater than 2.8.10 to resolve the issue. As a temporary workaround, consider restricting the use of Socket.IO messages to minimize the risk of exploitation.

Fix

DoS

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2023-30591

Affected Products

Nodebb