GHSA-pfj7-2qfw-vwgm

Suggest an improvement
Source
https://github.com/advisories/GHSA-pfj7-2qfw-vwgm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-pfj7-2qfw-vwgm/GHSA-pfj7-2qfw-vwgm.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-pfj7-2qfw-vwgm
Aliases
Related
Published
2021-11-30T22:20:43Z
Modified
2023-11-01T04:56:44.611447Z
Severity
  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N CVSS Calculator
Summary
NodeBB vulnerable to path traversal in translator module
Details

Impact

Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected languages/ directory.

Patches

The vulnerability has been patched as of v1.18.5.

Workarounds

Cherry-pick commit hash c8b2fc46dc698db687379106b3f01c71b80f495f to receive this patch in lieu of a full upgrade.

For more information

If you have any questions or comments about this advisory: * Email us at security@nodebb.org

Database specific
{
    "nvd_published_at": "2021-11-29T20:15:00Z",
    "cwe_ids": [
        "CWE-22"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2021-11-30T14:35:14Z"
}
References

Affected packages

npm / nodebb

Package

Affected ranges

Type
SEMVER
Events
Introduced
1.0.4
Fixed
1.18.5