CVE-2024-43409
CVSS V2 None
CVSS V3 None
Description
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.
Overview
- CVE ID
- CVE-2024-43409
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-08-20T15:05:04.338Z
- Last Modified Date
- 2024-08-20T15:05:04.338Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/TryGhost/Ghost/security/advisories/GHSA-78x2-cwp9-5j42 | x_refsource_CONFIRM |
https://github.com/TryGhost/Ghost/commit/dac25612520b571f58679764ecc27109e641d1db | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-43409 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-43409 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-08-21 13:19:07 | Added to TrackCVE |