CVE-2023-31133: Ghost vulnerable to information disclosure of private API fields
(updated )
Impact
Due to a lack of validation when filtering on the public API endpoints, it is possible to reveal private fields via a brute force attack.
Ghost(Pro) has already been patched. We can find no evidence that the issue was exploited on Ghost(Pro) prior to the patch being added.
Self-hosters are impacted if running Ghost a version below v5.46.1. Immediate action should be taken to secure your site - see patches and workarounds below.
Patches
v5.46.1 contains a fix for this issue.
Workarounds
Add a block for requests to /ghost/api/content/*
where the filter
query parameter contains password
or email
.
For more information
If you have any questions or comments about this advisory:
- Email us at security@ghost.org
References
Detect and mitigate CVE-2023-31133 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →