Description
Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally allowed master token access to the API. The vulnerability has been patch as of v1.18.5. Users are advised to upgrade as soon as possible.
Remediation
References
https://blog.sonarsource.com/nodebb-remote-code-execution-with-one-shot/
https://github.com/NodeBB/NodeBB/commit/04dab1d550cdebf4c1567bca9a51f8b9ca48a500
https://github.com/NodeBB/NodeBB/releases/tag/v1.18.5
https://github.com/NodeBB/NodeBB/security/advisories/GHSA-hf2m-j98r-4fqw
Related Vulnerabilities
CVE-2020-36649 Vulnerability in maven package org.webjars.bowergithub.mholt:papaparse
CVE-2019-5786 Vulnerability in maven package org.webjars.npm:puppeteer
CVE-2022-45470 Vulnerability in maven package org.apache.hama:hama-core
CVE-2023-26108 Vulnerability in npm package @nestjs/core
CVE-2021-22569 Vulnerability in maven package com.google.protobuf:protobuf-java