Описание
Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.
EPSS
Процентиль: 10%
0.00211
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 5.3
debian
2 дня назад
Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access con ...
CVSS3: 5.3
github
2 дня назад
Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.
EPSS
Процентиль: 10%
0.00211
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-862