漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Ghost Content API filter bypass reveals private fields
Vulnerability Description
Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute force attack. If SQLite was used as the database password hashes were fully accessible. If MySQL was used as the database the password hashes' case (uppercase / lowercase) would have been lost, which would likely have rendered a further brute force attack on the discovered hashes fruitless. This vulnerability is fixed in 6.21.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
Ghost 信息泄露漏洞
Vulnerability Description
Ghost是Ghost基金会开源的一款内容管理平台。 Ghost 5.46.1版本至6.21.2之前版本存在安全漏洞,该漏洞源于对公开API端点过滤器的验证可被部分绕过,可能导致通过暴力攻击泄露私有字段。以下版本受到影响:5.46.1版本至6.21.2之前版本。
CVSS Information
N/A
Vulnerability Type
N/A