Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-31133— Ghost vulnerable to disclosure of private API fields

Quick assessment

Affected
TryGhost Ghost
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Ghost CMS是新加坡Ghost基金会的一套使用JavaScript编写的开源无头内容管理系统(CMS)。 Ghost 5.46.1 之前版本存在信息泄露漏洞,该漏洞源于在公共 API 端点上过滤时缺乏验证 , 可以通过暴力攻击来揭示私有字段。

CVSS 7.5 · High EPSS 45.71% · P99
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-31133

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Ghost vulnerable to disclosure of private API fields
Source: CVE Program / CVE List V5
Vulnerability Description
Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid subscriptions to members. Prior to version 5.46.1, due to a lack of validation when filtering on the public API endpoints, it is possible to reveal private fields via a brute force attack. Ghost(Pro) has already been patched. Maintainers can find no evidence that the issue was exploited on Ghost(Pro) prior to the patch being added. Self-hosters are impacted if running Ghost a version below v5.46.1. v5.46.1 contains a fix for this issue. As a workaround, add a block for requests to `/ghost/api/content/*` where the `filter` query parameter contains `password` or `email`.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
Ghost 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Ghost CMS是新加坡Ghost基金会的一套使用JavaScript编写的开源无头内容管理系统(CMS)。 Ghost 5.46.1 之前版本存在信息泄露漏洞,该漏洞源于在公共 API 端点上过滤时缺乏验证 , 可以通过暴力攻击来揭示私有字段。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
TryGhost Ghost < 5.46.1 -

II. Public POCs for CVE-2023-31133

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-31133

登录查看更多情报信息。

Patches & Fixes for CVE-2023-31133 (1)

Vendor Advisories for CVE-2023-31133 (1)

Other References for CVE-2023-31133 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-31133

No comments yet


Leave a comment