漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
Vulnerability Description
Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being shared between different visitors, an unauthenticated user could send an x-ghost-preview header that altered the rendered frontend response. In affected cache configurations, that response could be stored and served to subsequent visitors requesting the same page, allowing cache poisoning of request-specific preview output. When running Ghost's frontend and admin panel on the same domain this could be used to take over staff user accounts. When running these on different domains staff accounts have no exposure. This vulnerability is fixed in 6.37.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
通过缓存导致的信息暴露
Vulnerability Title
Ghost 信息泄露漏洞
Vulnerability Description
Ghost是Ghost基金会开源的一款内容管理平台。 Ghost 4.0.0版本至6.37.0之前版本存在信息泄露漏洞,该漏洞源于共享缓存层导致的缓存内容被不同访客共享,可能允许未经身份验证的用户发送x-ghost-preview标头改变前端响应,导致缓存投毒。
CVSS Information
N/A
Vulnerability Type
N/A