PT-2023-22800 · Nodebb · Nodebb

·

CVE-2023-30591

·

Published

2023-09-28

·

Updated

2023-10-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NodeBB versions <= 2.8.10
Description The issue allows unauthenticated attackers to trigger a crash in NodeBB when invoking eventName.startsWith() or eventName.toString(), while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name respectively.
Recommendations For NodeBB versions <= 2.8.10, update to a version greater than 2.8.10 to resolve the issue. As a temporary workaround, consider restricting the use of Socket.IO messages to minimize the risk of exploitation.

Exploit

Fix

DoS

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-30591

Affected Products

Nodebb