Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. nodebb
  4. ›
  5. CVE-2022-46164

CVE-2022-46164: Improper Initialization

December 5, 2022 (updated November 7, 2023)

NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1. Users are advised to upgrade. Users unable to upgrade may cherry-pick commit 48d143921753914da45926cca6370a92ed0c46b8 into their codebase to patch the exploit.

References

  • github.com/NodeBB/NodeBB/commit/48d143921753914da45926cca6370a92ed0c46b8
  • github.com/NodeBB/NodeBB/releases/tag/v2.6.1
  • github.com/NodeBB/NodeBB/security/advisories/GHSA-rf3g-v8p5-p675
  • github.com/advisories/GHSA-rf3g-v8p5-p675
  • nvd.nist.gov/vuln/detail/CVE-2022-46164

Code Behaviors & Features

Detect and mitigate CVE-2022-46164 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.6.1

Solution

Unfortunately, there is no solution available yet.

Impact 9.8 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-665: Improper Initialization

Source file

npm/nodebb/CVE-2022-46164.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:31 +0000.