CVE-2024-34559: WordPress Ghost plugin <= 1.4.0 - Sensitive Data Exposure via Log File vulnerability
Published May 9, 2024
·Updated
Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from n/a through 1.4.0.
Affected Software
2 affected components
Ghost Foundation Ghost<=1.4.0
WordPress Ghost plugin<=1.4.0
Remediation
Information
Update to 1.5.0 or a higher version.
Event History
May 9, 2024
CVE Published
via MITRE·12:03 PM
Data Sourced
via MITRE·12:03 PM
RemedyDescriptionSeverityWeakness
May 14, 2024
Data Sourced
via NVD·03:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34559?
CVE-2024-34559 is classified as a vulnerability that involves the insertion of sensitive information into log files.
2
How do I fix CVE-2024-34559?
Updating the Ghost Foundation Ghost software to version 1.4.1 or later will mitigate the vulnerability identified as CVE-2024-34559.
3
What versions of Ghost are affected by CVE-2024-34559?
CVE-2024-34559 affects Ghost versions from n/a through 1.4.0.
4
What is the impact of CVE-2024-34559?
The impact of CVE-2024-34559 includes potential exposure of sensitive information due to improper logging practices.
5
Is the WordPress Ghost plugin affected by CVE-2024-34559?
Yes, the WordPress Ghost plugin is affected if it is version 1.4.0 or earlier.