CVE-2023-26510: Medium severity ghost ghost node.js vulnerability
Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in which a contributor's draft can only be read by editors until published by an editor. NOTE: the vendor's position is that this behavior has no security impact.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26510?
The severity of CVE-2023-26510 is considered low as it pertains to an authorization bypass issue that does not pose significant security risks according to the vendor.
How do I fix CVE-2023-26510?
Currently, there is no official patch provided for CVE-2023-26510, and users are advised to restrict contributor access to sensitive draft posts.
What version of Ghost is affected by CVE-2023-26510?
CVE-2023-26510 affects Ghost version 5.35.0.
Can contributors view draft posts from other users due to CVE-2023-26510?
Yes, because of CVE-2023-26510, contributors are able to view draft posts of other users, which is contrary to typical access controls.
Is there a workaround for CVE-2023-26510?
A potential workaround for CVE-2023-26510 is to limit the roles and permissions of contributors in the Ghost platform.