CVE-2021-43786: API token verification can be bypassed
Published Nov 29, 2021
·Updated
Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally allowed master token access to the API. The vulnerability has been patch as of v1.18.5. Users are advised to upgrade as soon as possible.
Affected Software
1 affected component
nodebb Nodebb>=1.15.0<=1.18.4
Remediation
Event History
Nov 29, 2021
CVE Published
via MITRE·07:30 PM
Data Sourced
via MITRE·07:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-43786?
CVE-2021-43786 is a vulnerability in the Nodebb forum software that allows unauthorized access to the API using a master token.
2
What is the severity of CVE-2021-43786?
CVE-2021-43786 has a severity rating of 7.5 (critical).
3
How does CVE-2021-43786 affect Nodebb?
CVE-2021-43786 affects Nodebb versions 1.15.0 to 1.18.4, allowing unintended access to the API.
4
How can I fix CVE-2021-43786?
To fix CVE-2021-43786, users are advised to upgrade to Nodebb version 1.18.5 or later.
5
Where can I find more information about CVE-2021-43786?
You can find more information about CVE-2021-43786 on the SonarSource blog and the NodeBB GitHub page.