Junglewise Threat Intelligence

CVE-2022-36045: NodeBB cryptographically weak PRNG in password reset

CVE-2022-36045 · Severity: low · CVSS 3.1 · Published 2022-08-30

Technologies: NodeBB. Vendors: NodeBB.

Executive brief

NodeBB's password reset functionality uses a mathematically weak random number generator to create reset tokens, allowing attackers to guess valid reset codes and take over user accounts without their knowledge. An attacker only needs to know the target's email address, which may be publicly visible or guessable. This affects all NodeBB installations and enables full account compromise.

Technical details

The vulnerability exists in the `utils.generateUUID` helper function used by NodeBB's password reset mechanism. The function relies on JavaScript's `Math.random()` for generating reset codes, which is not cryptographically secure and its output is predictable. An attacker can use multiple password reset requests combined with brute-force or prediction techniques to calculate valid reset tokens for target accounts. No prior authentication or user interaction is required; the attacker only needs to know or guess the target's email address. Patches are available in versions 1.19.8 and 2.0.1, which replace the weak PRNG with a cryptographically secure random number generator.

Affected products

  • NodeBB NodeBB all versions up to and including 1.19.7 and 2.0.0

Timeline

  • 2022-08-24: disclosed
  • 2022-08-30: patched
  • 2022-08-30: advisory

References

Related threats