PT-2024-25905 · Ghost · Ghost

Published

2024-06-16

·

Updated

2025-06-23

·

CVE-2024-34451

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Ghost versions 5.85.1 and earlier
Description The issue allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. The vendor recommends installing Ghost with a reverse proxy that allows only trusted X-Forwarded-For headers.
Recommendations For Ghost versions 5.85.1 and earlier, consider installing a reverse proxy that filters and only allows trusted X-Forwarded-For headers to mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BIT-GHOST-2024-34451
CVE-2024-34451

Affected Products

Ghost