CVE-2021-43788: Path traversal in translator module of NobeBB
Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected languages/ directory. The vulnerability has been patched as of v1.18.5. Users are advised to upgrade as soon as possible.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-43788?
CVE-2021-43788 is a path traversal vulnerability in Nodebb, an open source Node.js based forum software, prior to version 1.18.5.
How severe is CVE-2021-43788?
CVE-2021-43788 has a severity level of medium (5).
What software versions are affected by CVE-2021-43788?
Versions prior to 1.18.5 of Nodebb are affected by CVE-2021-43788.
How can I fix CVE-2021-43788?
To fix CVE-2021-43788, it is recommended to upgrade to version 1.18.5 or later of Nodebb.
Is there any additional information about CVE-2021-43788?
For more information about CVE-2021-43788, you can refer to the following references: 1) [Blog Post by SonarSource](https://blog.sonarsource.com/nodebb-remote-code-execution-with-one-shot/), 2) [GitHub Commit](https://github.com/NodeBB/NodeBB/commit/c8b2fc46dc698db687379106b3f01c71b80f495f), 3) [GitHub Release](https://github.com/NodeBB/NodeBB/releases/tag/v1.18.5)