CVE-2021-39192: Privilege escalation: all users can access Admin-level API keys
Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authenticated users (including contributors) to view admin-level API keys via the integrations API endpoint, leading to a privilege escalation vulnerability. This issue is patched in Ghost version 4.10.0. As a workaround, disable all non-Administrator accounts to prevent API access. It is highly recommended to regenerate all API keys after patching or applying the workaround.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 4.10.0 - Configuration
As a workaround, disable all non-Administrator accounts to prevent API access (accounts other than Administrator should not be able to access the integrations API endpoint).
Ghost Disable all non-Administrator accounts = enabled - Operational
After patching or applying the workaround, regenerate all API keys.
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39192?
CVE-2021-39192 is classified as a high severity vulnerability due to potential privilege escalation.
How do I fix CVE-2021-39192?
To fix CVE-2021-39192, upgrade Ghost to version 4.10.0 or later.
Who is affected by CVE-2021-39192?
All authenticated users, including contributors, are affected by CVE-2021-39192.
What type of vulnerability is CVE-2021-39192?
CVE-2021-39192 is a privilege escalation vulnerability in Ghost's integration API.
What versions of Ghost are vulnerable to CVE-2021-39192?
Ghost versions between 4.0.0 and 4.9.4 are vulnerable to CVE-2021-39192.