Medium severity6.3NVD Advisory· Published Mar 28, 2024· Updated Jun 17, 2026
CVE-2024-29316
CVE-2024-29316
Description
NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via "isadmin":true.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nodebbnpm | < 3.6.7 | 3.6.7 |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-qc99-r4wh-c8h6ghsaADVISORY
- medium.com/%40krityamkarma858041/broken-access-control-nodebb-v3-6-7-eebc59c24debnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-29316ghsaADVISORY
- nodebb.org/bountyghsaWEB
- nodebb.org/bounty/nvdProduct
News mentions
0No linked articles in our index yet.