NodeBB vulnerable to path traversal in translator module
Description
        Published by the National Vulnerability Database
      Nov 29, 2021 
    
  
        Reviewed
      Nov 30, 2021 
    
  
        Published to the GitHub Advisory Database
      Nov 30, 2021 
    
  
        Last updated
      Feb 1, 2023 
    
  
Impact
Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected
languages/directory.Patches
The vulnerability has been patched as of v1.18.5.
Workarounds
Cherry-pick commit hash
c8b2fc46dc698db687379106b3f01c71b80f495fto receive this patch in lieu of a full upgrade.For more information
If you have any questions or comments about this advisory:
References