CVE-2023-2850: Medium severity nodebb vulnerability

Published Jul 25, 2023
·
Updated

Impact

Private messages or posts might be leaked to third parties if victim opens the attackers site while browsing nodebb.

Patches

Patched in v3.1.3 Backported to v2.x line via v2.8.13

Workarounds

Users can cherry-pick https://github.com/NodeBB/NodeBB/commit/51096ad2345fb1d1380bec0a447113489ef6c359 if they are on v3.x

If you are running v2.x of NodeBB, you can cherry-pick a5d92da9ddac5607ab7f737520a66eaed6d3ddee followed by 62e162cf1e735e42462be1db9b4954b5a69accdf

Other sources

NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.

Affected Software

4 affected componentsFixes available
npm/nodebb<2.8.13
2.8.13
npm/nodebb>=3.0.0<3.1.3
3.1.3
nodebb Nodebb<2.8.13
nodebb Nodebb>=3.0.0<3.1.3

Event History

Jul 25, 2023
CVE Published
via MITRE·11:13 AM
Data Sourced
via MITRE·11:13 AM
DescriptionSeverityWeakness
Data Sourced
12:15 PM
Description
Advisory Published
06:04 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the impact of CVE-2023-2850?

Private messages or posts might be leaked to third parties if the victim opens the attacker's site while browsing NodeBB.

2

How can I fix CVE-2023-2850?

Update NodeBB to version 3.1.3 or apply the patch mentioned in the references.

3

What are the patches for CVE-2023-2850?

The vulnerability has been patched in NodeBB version 3.1.3 and backported to the v2.x line via v2.8.13.

4

Are there any workarounds for CVE-2023-2850?

No specific workarounds are mentioned for this vulnerability.

5

What is the severity level of CVE-2023-2850?

The severity level of CVE-2023-2850 is medium with a CVSS score of 4.7.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203