CVE-2024-34451: Critical severity ghost foundation ghost vulnerability
Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34451?
CVE-2024-34451 is considered a moderate severity vulnerability due to its potential for unauthorized access through authentication bypass.
How do I fix CVE-2024-34451?
To fix CVE-2024-34451, ensure that Ghost is deployed behind a secure reverse proxy that only allows trusted X-Forwarded-For headers.
Which versions of Ghost are affected by CVE-2024-34451?
CVE-2024-34451 affects Ghost versions up to and including 5.85.1.
Can CVE-2024-34451 be exploited remotely?
Yes, CVE-2024-34451 can be exploited remotely by attackers manipulating X-Forwarded-For headers.
What does CVE-2024-34451 allow attackers to do?
CVE-2024-34451 allows attackers to bypass authentication rate-limit protections in Ghost.