4.7

CVE-2023-2850

NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NodebbNodebb Version < 2.8.13
NodebbNodebb Version >= 3.0.0 < 3.1.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.193
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.7 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
report@snyk.io 4.7 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
CWE-1385 Missing Origin Validation in WebSockets

The product uses a WebSocket, but it does not properly verify that the source of data or communication is valid.

CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

https://github.com/NodeBB/NodeBB/commit/51096ad2345fb1d1380bec0a447113489ef6c359
Patch
https://github.com/NodeBB/NodeBB/releases/tag/v3.1.3
Release Notes
https://github.com/NodeBB/NodeBB/security/advisories/GHSA-4qcv-qf38-5j3j
Patch
Vendor Advisory