QID 983309

QID 983309: Nodejs (npm) Security Update for nodebb (GHSA-wx69-rvg3-x7fc)

Security update has been released for nodebb to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

A prototype pollution vulnerability in the uploader module allowed a malicious user to inject arbitrary data (i.e. javascript) into the DOM, theoretically allowing for an account takeover when used in conjunction with a path traversal vulnerability disclosed at the same time as this report.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    The vulnerability has been patched as of v1.18.5.Workaround:
    Cherry-pick commit hash 1783f918bc19568f421473824461ff2ed7755e4c to receive this patch in lieu of a full upgrade.
    Vendor References

    CVEs related to QID 983309

    Software Advisories
    Advisory ID Software Component Link
    GHSA-wx69-rvg3-x7fc nodebb URL Logo github.com/advisories/GHSA-wx69-rvg3-x7fc