First published: Sun Mar 05 2023(Updated: )
Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in which a contributor's draft can only be read by editors until published by an editor. NOTE: the vendor's position is that this behavior has no security impact.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ghost Ghost Node.js | =5.35.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-26510 is considered low as it pertains to an authorization bypass issue that does not pose significant security risks according to the vendor.
Currently, there is no official patch provided for CVE-2023-26510, and users are advised to restrict contributor access to sensitive draft posts.
CVE-2023-26510 affects Ghost version 5.35.0.
Yes, because of CVE-2023-26510, contributors are able to view draft posts of other users, which is contrary to typical access controls.
A potential workaround for CVE-2023-26510 is to limit the roles and permissions of contributors in the Ghost platform.