logo

CVE-2021-43788 nodebb

Package

Manager: npm
Name: nodebb
Vulnerable Version: >=1.0.4 <1.18.5

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.0555 pctl0.89908

Details

NodeBB vulnerable to path traversal in translator module ### Impact Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected `languages/` directory. ### Patches The vulnerability has been patched as of v1.18.5. ### Workarounds Cherry-pick commit hash `c8b2fc46dc698db687379106b3f01c71b80f495f` to receive this patch in lieu of a full upgrade. ### For more information If you have any questions or comments about this advisory: * Email us at [security@nodebb.org](mailto:security@nodebb.org)

Metadata

Created: 2021-11-30T22:20:43Z
Modified: 2022-09-14T20:37:56Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-pfj7-2qfw-vwgm/GHSA-pfj7-2qfw-vwgm.json
CWE IDs: ["CWE-22"]
Alternative ID: GHSA-pfj7-2qfw-vwgm
Finding: F063
Auto approve: 1