QID 983308
QID 983308: Nodejs (npm) Security Update for nodebb (GHSA-hf2m-j98r-4fqw)
Security update has been released for nodebb to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Incorrect logic present in the token verification step unintentionally allowed master token access to the API.
Solution
The vulnerability has been patch as of v1.18.5.Workaround:
Cherry-pick commit hash 04dab1d550cdebf4c1567bca9a51f8b9ca48a500 to receive this patch in lieu of a full upgrade.
Cherry-pick commit hash 04dab1d550cdebf4c1567bca9a51f8b9ca48a500 to receive this patch in lieu of a full upgrade.
Vendor References
- GHSA-hf2m-j98r-4fqw -
github.com/advisories/GHSA-hf2m-j98r-4fqw
CVEs related to QID 983308
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hf2m-j98r-4fqw | nodebb |
|