VulnerabilityModified
CVE-2021-43788
Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected `languages/` directory.
MEDIUM 5.0EPSS 25.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 25.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected `languages/` directory. The vulnerability has been patched as of v1.18.5. Users are advised to upgrade as soon as possible.
- CVSS 3.1
- 5.0 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- EPSS
- 25.84% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- nodebb/nodebb
- Source
- security-advisories@github.com
References
- https://blog.sonarsource.com/nodebb-remote-code-execution-with-one-shot/Exploit, Third Party Advisory
- https://github.com/NodeBB/NodeBB/commit/c8b2fc46dc698db687379106b3f01c71b80f495fPatch, Third Party Advisory
- https://github.com/NodeBB/NodeBB/releases/tag/v1.18.5Release Notes, Third Party Advisory
- https://github.com/NodeBB/NodeBB/security/advisories/GHSA-pfj7-2qfw-vwgmThird Party Advisory
- https://blog.sonarsource.com/nodebb-remote-code-execution-with-one-shot/Exploit, Third Party Advisory
- https://github.com/NodeBB/NodeBB/commit/c8b2fc46dc698db687379106b3f01c71b80f495fPatch, Third Party Advisory
- https://github.com/NodeBB/NodeBB/releases/tag/v1.18.5Release Notes, Third Party Advisory
- https://github.com/NodeBB/NodeBB/security/advisories/GHSA-pfj7-2qfw-vwgmThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.