Description
NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1957 | NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker. |
Github GHSA |
GHSA-4qcv-qf38-5j3j | Unintentional leakage of private information via cross-origin websocket session hijacking |
References
History
Tue, 15 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-10-15T19:05:55.858Z
Reserved: 2023-05-23T11:27:01.949Z
Link: CVE-2023-2850
Updated: 2024-08-02T06:33:05.820Z
Status : Modified
Published: 2023-07-25T12:15:10.837
Modified: 2024-11-21T07:59:25.033
Link: CVE-2023-2850
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA