NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.
The product uses a WebSocket, but it does not properly verify that the source of data or communication is valid.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
https://github.com/NodeBB/NodeBB/security/advisories/GHSA-4qcv-qf38-5j3j | patch vendor advisory |
https://github.com/NodeBB/NodeBB/commit/51096ad2345fb1d1380bec0a447113489ef6c359 | patch |
https://github.com/NodeBB/NodeBB/releases/tag/v3.1.3 | release notes |