We have released NodeBB v1.18.5. This release contains important security fixes.
Upgrading is strongly advised.
Please check our GitHub for details:
@arutemu Link. Nodebb supported Nodejs 8. I install Nodejs 8 for NodeBB and Ghost, this is working and look good!
@Rusdy-MT It seems to me like they have revamped this option. It's now some kind of "group privilege" now. You can toggle it under ACP -> Manage -> Privileges. This came out of nowhere for me as well...
looks very good, thanks guys 😄
Thanks to @psychobunny for the excellent guide!
Setting up a NodeBB Forum “for Dummies”
A bug in our validation logic made it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server.
We have resolved this in the latest version of NodeBB, and the fix has already been rolled out as a patch on all of our hosted customers.
For more information on the vulnerability as well as instructions on how to resolve this issue, please have a look here: https://github.com/NodeBB/NodeBB/security/advisories/GHSA-hr66-c8pg-5mg7
Click here to see the full blog post