Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w23p-63vq-8j33

Опубликовано: 01 окт. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.

Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.

EPSS

Процентиль: 10%
0.00211
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.3
nvd
2 дня назад

Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.

CVSS3: 5.3
debian
2 дня назад

Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access con ...

EPSS

Процентиль: 10%
0.00211
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-862