NodeBB vulnerable to account takeover via prototype vulnerability
Description
Published by the National Vulnerability Database
Dec 5, 2022
Published to the GitHub Advisory Database
Dec 5, 2022
Reviewed
Dec 5, 2022
Last updated
Jan 31, 2023
Impact
Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts.
Patches
Patched in 2.6.1
Workarounds
Site maintainers can cherry-pick NodeBB/NodeBB@48d1439 into their codebase to patch the exploit.
For more information
If you have any questions or comments about this advisory:
Discuss it on our community forum
Email us at [email protected]
References