Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78x2-cwp9-5j42

Опубликовано: 20 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 6.5

Описание

Ghost's improper authentication allows access to member information and actions

Impact

Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information.

Vulnerable versions

This security vulnerability is present in Ghost v4.46.0-v5.89.5.

Ghost(Pro) customers are automatically updated to fixed versions ahead of disclosure.

If you're a self-hoster, please follow our update instructions.

Patches

v5.89.5 contains a fix for this issue.

Workarounds

Disable site membership in Ghost settings.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

ghost

npm
Затронутые версииВерсия исправления

>= 4.46.0, < 5.89.5

5.89.5

Наименование

@tryghost/portal

npm
Затронутые версииВерсия исправления

>= 1.22.2, < 2.39.0

2.39.0

EPSS

Процентиль: 63%
0.00454
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-284
CWE-287

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.

CVSS3: 6.5
debian
больше 1 года назад

Ghost is a Node.js content management system. Improper authentication ...

EPSS

Процентиль: 63%
0.00454
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-284
CWE-287