VulnerabilityModified
CVE-2021-43786
In affected versions incorrect logic present in the token verification step unintentionally allowed master token access to the API.
HIGH 7.5EPSS 2.29%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally allowed master token access to the API. The vulnerability has been patch as of v1.18.5. Users are advised to upgrade as soon as possible.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.29% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- nodebb/nodebb
- Source
- security-advisories@github.com
References
- https://blog.sonarsource.com/nodebb-remote-code-execution-with-one-shot/Exploit, Third Party Advisory
- https://github.com/NodeBB/NodeBB/commit/04dab1d550cdebf4c1567bca9a51f8b9ca48a500Patch, Third Party Advisory
- https://github.com/NodeBB/NodeBB/releases/tag/v1.18.5Release Notes, Third Party Advisory
- https://github.com/NodeBB/NodeBB/security/advisories/GHSA-hf2m-j98r-4fqwThird Party Advisory
- https://blog.sonarsource.com/nodebb-remote-code-execution-with-one-shot/Exploit, Third Party Advisory
- https://github.com/NodeBB/NodeBB/commit/04dab1d550cdebf4c1567bca9a51f8b9ca48a500Patch, Third Party Advisory
- https://github.com/NodeBB/NodeBB/releases/tag/v1.18.5Release Notes, Third Party Advisory
- https://github.com/NodeBB/NodeBB/security/advisories/GHSA-hf2m-j98r-4fqwThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.