Vulnerability Description
NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via "isadmin":true.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nodebb | Nodebb | 3.6.7 |
References
- https://medium.com/%40krityamkarma858041/broken-access-control-nodebb-v3-6-7-eebThird Party Advisory
- https://nodebb.org/bounty/Product
- https://medium.com/%40krityamkarma858041/broken-access-control-nodebb-v3-6-7-eebThird Party Advisory
- https://nodebb.org/bounty/Product
FAQ
What is CVE-2024-29316?
CVE-2024-29316 is a vulnerability with a CVSS score of 6.3 (MEDIUM). NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via "isadmin":true.
How severe is CVE-2024-29316?
CVE-2024-29316 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-29316?
Check the references section above for vendor advisories and patch information. Affected products include: Nodebb Nodebb.