
Cloud Vulnerability DB
A community-led vulnerabilities database
NodeBB version 3.6.7 was discovered to contain an Incorrect Access Control vulnerability. The vulnerability was disclosed on March 28, 2024, affecting the group section functionality of NodeBB. This security flaw allows low-privileged attackers to access restricted administrative tabs by manipulating certain JSON response parameters (Medium Blog).
The vulnerability exists in the group section of NodeBB where the application's response handling for group requests can be exploited. An attacker can intercept the response and modify specific JSON parameters including 'system', 'private', 'isMember', 'isPending', 'isInvited', 'isOwner', and most critically 'isAdmin' to gain unauthorized access. The CVSS v3.1 base score assigned by CISA-ADP is 6.3 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L (NVD).
The successful exploitation of this vulnerability allows attackers to access administrative tabs and information that should only be accessible to administrators. This represents a significant breach of access control mechanisms and could potentially expose sensitive administrative functions and data (Medium Blog).
The vulnerability can be exploited by a low-privileged user by navigating to the group section, intercepting the response for group requests, and modifying specific JSON parameters in the response. The attack requires minimal technical expertise and can be executed remotely (Medium Blog).
The vulnerability has been acknowledged and resolved by the NodeBB development team in the same version. Users are advised to ensure they are running the patched version of the software (Medium Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."