CVE-2022-36076: Account takeover via SSO plugins in NodeBB
NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily strict conditional in the code handling the first step of the SSO process, the pre-existing logic that added (and later checked) a nonce was inadvertently rendered opt-in instead of opt-out. This re-exposed a vulnerability in that a specially crafted Man-in-the-Middle (MITM) attack could theoretically take over another user account during the single sign-on process. The issue has been fully patched in version 1.17.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-36076?
CVE-2022-36076 is a vulnerability in NodeBB Forum Software that allows an attacker to bypass the Single Sign-On (SSO) process and gain unauthorized access.
How does CVE-2022-36076 affect NodeBB Forum Software?
CVE-2022-36076 affects NodeBB Forum Software versions up to and excluding 1.17.2.
What is the severity of CVE-2022-36076?
CVE-2022-36076 has a severity rating of 7.5 (High).
How can an attacker exploit CVE-2022-36076?
An attacker can exploit CVE-2022-36076 by manipulating the Conditional Access Code during the Single Sign-On process to bypass authentication.
Is there a fix available for CVE-2022-36076?
Yes, a fix for CVE-2022-36076 is available in the latest version of NodeBB Forum Software.