GHSA-rf3g-v8p5-p675
NodeBB vulnerable to account takeover via prototype vulnerability
Quick fix
GHSA-rf3g-v8p5-p675 — nodebb: upgrade to the fixed version with the command below.
npm install nodebb@2.6.1Details
### Impact Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts.
### Patches Patched in 2.6.1
### Workarounds Site maintainers can cherry-pick https://github.com/NodeBB/NodeBB/commit/48d143921753914da45926cca6370a92ed0c46b8 into their codebase to patch the exploit.
### For more information If you have any questions or comments about this advisory:
Discuss it on [our community forum](https://github.com/NodeBB/NodeBB/security/advisories/community.nodebb.org/) Email us at [support@nodebb.org](mailto:support@nodebb.org)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/NodeBB/NodeBB/security/advisories/GHSA-rf3g-v8p5-p675[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-46164[ADVISORY]
- https://github.com/NodeBB/NodeBB/commit/48d143921753914da45926cca6370a92ed0c46b8[WEB]
- https://github.com/NodeBB/NodeBB[PACKAGE]
- https://github.com/NodeBB/NodeBB/releases/tag/v2.6.1[WEB]