CVE-2021-39192

Published
View on NVD ↗
CVSS v3
6.5
MEDIUM
CVSS v2
6.5
MEDIUM
Affected
1
PROJECT

Description

Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authenticated users (including contributors) to view admin-level API keys via the integrations API endpoint, leading to a privilege escalation vulnerability. This issue is patched in Ghost version 4.10.0. As a workaround, disable all non-Administrator accounts to prevent API access. It is highly recommended to regenerate all API keys after patching or applying the workaround.

Independent technology for modern publishing, memberships, subscriptions and newsletters.
GitHubGitHub
54.2K