QID 983199
QID 983199: Nodejs (npm) Security Update for nodebb-plugin-blog-comments (GHSA-43m5-c88r-cjvv)
Security update has been released for nodebb-plugin-blog-comments to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Due to lack of CSRF validation, a logged in user is potentially vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum.
Solution
Upgrade to the latest version v0.7.0Workaround:
You can cherry-pick the following commit: [https://github.com/psychobunny/nodebb-plugin-blog-comments/commit/cf43beedb05131937ef46f365ab0a0c6fa6ac618](https://github.com/psychobunny/nodebb-plugin-blog-comments/commit/cf43beedb05131937ef46f365ab0a0c6fa6ac618)
You can cherry-pick the following commit: [https://github.com/psychobunny/nodebb-plugin-blog-comments/commit/cf43beedb05131937ef46f365ab0a0c6fa6ac618](https://github.com/psychobunny/nodebb-plugin-blog-comments/commit/cf43beedb05131937ef46f365ab0a0c6fa6ac618)
Vendor References
- GHSA-43m5-c88r-cjvv -
github.com/advisories/GHSA-43m5-c88r-cjvv
CVEs related to QID 983199
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-43m5-c88r-cjvv | nodebb-plugin-blog-comments |
|