CVE-2022-41697: Medium severity ghost ghost node.js vulnerability
Published Dec 22, 2022
·Updated
A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTTP requests to trigger this vulnerability.
Affected Software
1 affected component
Ghost Ghost Node.js=5.9.4
Event History
Dec 22, 2022
CVE Published
10:15 AM
Dec 23, 2022
CVE Published
via MITRE·11:03 PM
Data Sourced
via MITRE·11:03 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-41697?
CVE-2022-41697 has a medium severity rating as it allows for user enumeration through specially-crafted HTTP requests.
2
How do I fix CVE-2022-41697?
To fix CVE-2022-41697, upgrade to the latest version of Ghost that addresses the user enumeration vulnerability.
3
What versions of Ghost are affected by CVE-2022-41697?
CVE-2022-41697 specifically affects Ghost version 5.9.4.
4
What kind of information can be disclosed through CVE-2022-41697?
CVE-2022-41697 can lead to the disclosure of sensitive information related to user accounts.
5
Can CVE-2022-41697 be exploited remotely?
Yes, CVE-2022-41697 can be exploited remotely by sending a series of HTTP requests.