QID 983309
QID 983309: Nodejs (npm) Security Update for nodebb (GHSA-wx69-rvg3-x7fc)
Security update has been released for nodebb to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A prototype pollution vulnerability in the uploader module allowed a malicious user to inject arbitrary data (i.e. javascript) into the DOM, theoretically allowing for an account takeover when used in conjunction with a path traversal vulnerability disclosed at the same time as this report.
Solution
The vulnerability has been patched as of v1.18.5.Workaround:
Cherry-pick commit hash 1783f918bc19568f421473824461ff2ed7755e4c to receive this patch in lieu of a full upgrade.
Cherry-pick commit hash 1783f918bc19568f421473824461ff2ed7755e4c to receive this patch in lieu of a full upgrade.
Vendor References
- GHSA-wx69-rvg3-x7fc -
github.com/advisories/GHSA-wx69-rvg3-x7fc
CVEs related to QID 983309
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wx69-rvg3-x7fc | nodebb |
|