QID 983199

QID 983199: Nodejs (npm) Security Update for nodebb-plugin-blog-comments (GHSA-43m5-c88r-cjvv)

Security update has been released for nodebb-plugin-blog-comments to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Due to lack of CSRF validation, a logged in user is potentially vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Upgrade to the latest version v0.7.0Workaround:
    You can cherry-pick the following commit: [https://github.com/psychobunny/nodebb-plugin-blog-comments/commit/cf43beedb05131937ef46f365ab0a0c6fa6ac618](https://github.com/psychobunny/nodebb-plugin-blog-comments/commit/cf43beedb05131937ef46f365ab0a0c6fa6ac618)
    Vendor References

    CVEs related to QID 983199

    Software Advisories
    Advisory ID Software Component Link
    GHSA-43m5-c88r-cjvv nodebb-plugin-blog-comments URL Logo github.com/advisories/GHSA-43m5-c88r-cjvv