CVE-2024-34448: High severity ghost vulnerability
Published May 22, 2024
·Updated
Ghost before 5.82.0 allows CSV Injection during a member CSV export.
Affected Software
2 affected componentsFixes available
npm/@tryghost/members-csv<5.82.0
5.82.0
Ghost Ghost Node.js<5.82.0
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 22, 2024
CVE Published
via NVD·04:15 PM
Data Sourced
via NVD·04:15 PM
Description
Advisory Published
via GitHub·06:30 PM
Aug 10, 2024
Data Sourced
via MITRE·03:57 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-34448?
CVE-2024-34448 is classified as a medium severity vulnerability due to its potential for CSV Injection during member CSV exports.
2
How do I fix CVE-2024-34448?
To fix CVE-2024-34448, upgrade to version 5.82.0 or later of the @tryghost/members-csv package.
3
What software is affected by CVE-2024-34448?
CVE-2024-34448 affects the @tryghost/members-csv package versions prior to 5.82.0.
4
What type of vulnerability is CVE-2024-34448?
CVE-2024-34448 is a CSV Injection vulnerability that allows malicious input to be executed when members data is exported.
5
Can CVE-2024-34448 be exploited remotely?
Yes, CVE-2024-34448 can be exploited remotely by attackers who can manipulate the CSV export functionality.