5.7

CVE-2023-26510

Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in which a contributor's draft can only be read by editors until published by an editor. NOTE: the vendor's position is that this behavior has no security impact.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GhostGhost Version5.35.0 SwPlatformnode.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.454
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.7 2.1 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://ghost.org/docs/security/
Vendor Advisory
https://gist.github.com/yurahod/2e11eabbe4b92ef1d44b08e37023ecfb
Third Party Advisory
https://gist.github.com/yurahod/828d5e6a077c12f3f74c6485d1c7f0e7
Third Party Advisory