QID 983308

QID 983308: Nodejs (npm) Security Update for nodebb (GHSA-hf2m-j98r-4fqw)

Security update has been released for nodebb to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Incorrect logic present in the token verification step unintentionally allowed master token access to the API.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vulnerability has been patch as of v1.18.5.Workaround:
    Cherry-pick commit hash 04dab1d550cdebf4c1567bca9a51f8b9ca48a500 to receive this patch in lieu of a full upgrade.
    Vendor References

    CVEs related to QID 983308

    Software Advisories
    Advisory ID Software Component Link
    GHSA-hf2m-j98r-4fqw nodebb URL Logo github.com/advisories/GHSA-hf2m-j98r-4fqw