CVE-2023-2850: Medium severity nodebb vulnerability
Impact
Private messages or posts might be leaked to third parties if victim opens the attackers site while browsing nodebb.
Patches
Patched in v3.1.3 Backported to v2.x line via v2.8.13
Workarounds
Users can cherry-pick https://github.com/NodeBB/NodeBB/commit/51096ad2345fb1d1380bec0a447113489ef6c359 if they are on v3.x
If you are running v2.x of NodeBB, you can cherry-pick a5d92da9ddac5607ab7f737520a66eaed6d3ddee followed by 62e162cf1e735e42462be1db9b4954b5a69accdf
Other sources
NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the impact of CVE-2023-2850?
Private messages or posts might be leaked to third parties if the victim opens the attacker's site while browsing NodeBB.
How can I fix CVE-2023-2850?
Update NodeBB to version 3.1.3 or apply the patch mentioned in the references.
What are the patches for CVE-2023-2850?
The vulnerability has been patched in NodeBB version 3.1.3 and backported to the v2.x line via v2.8.13.
Are there any workarounds for CVE-2023-2850?
No specific workarounds are mentioned for this vulnerability.
What is the severity level of CVE-2023-2850?
The severity level of CVE-2023-2850 is medium with a CVSS score of 4.7.