PT-2023-23677 · Ghost · Ghost

Fuomag9

·

Publicado

2023-05-05

·

Atualizado

2024-03-06

·

CVE-2023-32235

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ghost versions prior to 5.42.1
Description The issue allows remote attackers to read arbitrary files within the active theme's folder via directory traversal using the /assets/built%2F..%2F..%2F/ endpoint. This occurs in the frontend/web/middleware/static-theme.js file.
Recommendations For Ghost versions prior to 5.42.1, update to version 5.42.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the /assets/built/ endpoint to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-GHOST-2023-32235
CVE-2023-32235
GHSA-WF7X-FH6W-34R6

Produtos afetados

Ghost