Skip to content

API token verification can be bypassed

Critical
julianlam published GHSA-hf2m-j98r-4fqw Nov 27, 2021

Package

nodebb

Affected versions

1.15.0 - 1.18.4

Patched versions

1.18.5

Description

Impact

Incorrect logic present in the token verification step unintentionally allowed master token access to the API.

Patches

The vulnerability has been patch as of v1.18.5.

Workarounds

Cherry-pick commit hash 04dab1d to receive this patch in lieu of a full upgrade.

For more information

If you have any questions or comments about this advisory:

Severity

Critical

CVE ID

CVE-2021-43786

Weaknesses

Credits