Skip to content

Path traversal in translator module

Critical
julianlam published GHSA-pfj7-2qfw-vwgm Nov 27, 2021

Package

nodebb

Affected versions

1.0.4 - 1.18.4

Patched versions

1.18.5

Description

Impact

Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected languages/ directory.

Patches

The vulnerability has been patched as of v1.18.5.

Workarounds

Cherry-pick commit hash c8b2fc46dc698db687379106b3f01c71b80f495f to receive this patch in lieu of a full upgrade.

For more information

If you have any questions or comments about this advisory:

Severity

Critical

CVE ID

CVE-2021-43788

Weaknesses

Credits