Junglewise Threat Intelligence

CVE-2022-3978: NodeBB Cross-Site Request Forgery in registration abort

CVE-2022-3978 · Severity: low · CVSS 3.1 · Published 2022-11-13

Technologies: NodeBB. Vendors: NodeBB.

Executive brief

NodeBB is a popular open-source forum and community platform. The `/register/abort` endpoint lacked CSRF token validation, allowing attackers to craft malicious web pages that could disrupt user registration when viewed by site visitors. While the impact is limited to preventing legitimate registrations, this represents a best-practice security gap in a web application handling user authentication.

Technical details

A Cross-Site Request Forgery (CWE-352) vulnerability was discovered in the `/register/abort` endpoint of NodeBB up to version 2.5.7. The endpoint, which terminates user registration sessions, did not validate CSRF tokens on POST requests, allowing attackers to construct forged requests triggered by visiting a malicious website. An attacker could craft a page that, when visited by a user in an active registration flow, would automatically submit a request to abort their registration without their knowledge. The attack requires network access and user interaction (visiting a malicious page), but no authentication. The vulnerability was patched in version 2.5.8 by adding CSRF token validation to the endpoint and updating the registration completion template to include the token in abort requests (commit 2f9d8c3).

Affected products

  • NodeBB NodeBB up to 2.5.7

Timeline

  • 2022-11-13: disclosed: Vulnerability published in OSV
  • 2022-11-09: patched: Fixed in NodeBB v2.5.8

References

Related threats