Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5jm7-g527-m694

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.9

Описание

Publify exposes article metadata

Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users.

Пакеты

Наименование

publify_core

rubygems
Затронутые версииВерсия исправления

< 9.2.8

9.2.8

EPSS

Процентиль: 49%
0.00262
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.9
nvd
больше 3 лет назад

Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users.

EPSS

Процентиль: 49%
0.00262
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-863