CVE-2020-8134: SSRF
Published Mar 20, 2020
·Updated
Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal systems.
Affected Software
1 affected component
Ghost Ghost Node.js<3.10.0
Remediation
Patch Available
Event History
Mar 20, 2020
CVE Published
via MITRE·06:26 PM
Data Sourced
via MITRE·06:26 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-8134?
CVE-2020-8134 is a server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 that allows an attacker to scan local or external network or otherwise interact with internal systems.
2
How severe is CVE-2020-8134?
CVE-2020-8134 has a severity rating of 8.1 (high).
3
What software versions are affected by CVE-2020-8134?
Ghost CMS versions before 3.10.0 are affected by CVE-2020-8134.
4
How can I fix CVE-2020-8134?
To fix CVE-2020-8134, it is recommended to upgrade Ghost CMS to version 3.10.0 or higher.
5
Where can I find more information about CVE-2020-8134?
You can find more information about CVE-2020-8134 at the following link: [CVE-2020-8134 - HackerOne](https://hackerone.com/reports/793704)