Unintentional leakage of private information via cross-origin websocket session hijacking
Description
Published by the National Vulnerability Database
Jul 25, 2023
Published to the GitHub Advisory Database
Jul 25, 2023
Reviewed
Jul 25, 2023
Last updated
Nov 10, 2023
Impact
Private messages or posts might be leaked to third parties if victim opens the attackers site while browsing nodebb.
Patches
Workarounds
Users can cherry-pick NodeBB/NodeBB@51096ad if they are on v3.x
If you are running v2.x of NodeBB, you can cherry-pick a5d92da9ddac5607ab7f737520a66eaed6d3ddee followed by 62e162cf1e735e42462be1db9b4954b5a69accdf
References