VDB
Sign up
CRITICAL9.8

GHSA-hf2m-j98r-4fqw

API token verification can be bypassed in NodeBB

Quick fix

GHSA-hf2m-j98r-4fqw — nodebb: upgrade to the fixed version with the command below.

npm install nodebb@1.18.5

Details

### Impact Incorrect logic present in the token verification step unintentionally allowed master token access to the API.

### Patches The vulnerability has been patch as of v1.18.5.

### Workarounds Cherry-pick commit hash 04dab1d550cdebf4c1567bca9a51f8b9ca48a500 to receive this patch in lieu of a full upgrade.

### For more information If you have any questions or comments about this advisory: * Email us at [security@nodebb.org](mailto:security@nodebb.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/nodebb
Introduced in: 1.15.0Fixed in: 1.18.5
Fixnpm install nodebb@1.18.5

References