PT-2023-22800 · Nodebb · Nodebb
Creastery
+1
·
Published
2023-09-28
·
Updated
2023-10-02
·
CVE-2023-30591
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NodeBB versions <= 2.8.10
Description
The issue allows unauthenticated attackers to trigger a crash in NodeBB when invoking
eventName.startsWith() or eventName.toString(), while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name respectively.Recommendations
For NodeBB versions <= 2.8.10, update to a version greater than 2.8.10 to resolve the issue.
As a temporary workaround, consider restricting the use of Socket.IO messages to minimize the risk of exploitation.
Fix
DoS
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nodebb