CVE-2024-29316: Medium severity npm/nodebb vulnerability
In NodeBB prior to 3.6.7 an attacker was able to access the restricted tabs for the Admin group which are only allowed the the administrators.
Other sources
NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via "isadmin":true.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29316?
CVE-2024-29316 is classified as a moderate severity vulnerability due to the risk of incorrect access control allowing unauthorized access to admin functionality.
How do I fix CVE-2024-29316?
To fix CVE-2024-29316, upgrade NodeBB to version 3.6.7 or later, where the access control issue has been resolved.
Who is affected by CVE-2024-29316?
Users running NodeBB versions prior to 3.6.7 are affected by CVE-2024-29316.
What kind of attack is possible with CVE-2024-29316?
CVE-2024-29316 allows a low-privileged attacker to access restricted admin tabs that should only be available to administrators.
How can I determine if my NodeBB version is vulnerable to CVE-2024-29316?
You can determine your vulnerability to CVE-2024-29316 by checking if your NodeBB version is before 3.6.7.