VYPR
Medium severity6.3NVD Advisory· Published Mar 28, 2024· Updated Jun 17, 2026

CVE-2024-29316

CVE-2024-29316

Description

NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via "isadmin":true.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
nodebbnpm
< 3.6.73.6.7

Affected products

3
  • ghsa-coords
    Range: < 3.6.7
  • NodeBB/Nodebb2 versions
    cpe:2.3:a:nodebb:nodebb:3.6.7:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:nodebb:nodebb:3.6.7:*:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.