Vulnerability record · CVE-2022-36076 · published 2 September 2022
CVE-2022-36076: Nodebb cross-site request forgery vulnerability
Nodebb · Nodebb
NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily strict conditional in the code handling the first step of the SSO process, the pre-existing logic that added (and later checked) a nonce was inadvertently rendered opt-in instead of opt-out. This re-exposed a vulnerability in that a specially crafted Man-in-the-Middle (MITM) attack could theoretically take over another user account during the single sign-on process. The issue has been fully patched in version 1.17.2.
Description
NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily strict conditional in the code handling the first step of the SSO process, the pre-existing logic that added (and later checked) a nonce was inadvertently rendered opt-in instead of opt-out. This re-exposed a vulnerability in that a specially crafted Man-in-the-Middle (MITM) attack could theoretically take over another user account during the single sign-on process. The issue has been fully patched in version 1.17.2.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blogs.opera.com/security/2022/03/bug-bounty-adventures-a-nodebb-0-day/ | ExploitThird Party Advisory |
| https://github.com/NodeBB/NodeBB/commit/a2400f6baff44cb2996487bcd0cc6e2acc74b3d4 | PatchThird Party Advisory |
| https://github.com/NodeBB/NodeBB/security/advisories/GHSA-xmgg-fx9p-prq6 | ExploitPatchThird Party Advisory |
| https://blogs.opera.com/security/2022/03/bug-bounty-adventures-a-nodebb-0-day/ | ExploitThird Party Advisory |
| https://github.com/NodeBB/NodeBB/commit/a2400f6baff44cb2996487bcd0cc6e2acc74b3d4 | PatchThird Party Advisory |
| https://github.com/NodeBB/NodeBB/security/advisories/GHSA-xmgg-fx9p-prq6 | ExploitPatchThird Party Advisory |
Track CVE-2022-36076 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-36076), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.