CVE-2024-43409: Ghost's improper authentication allows access to member information and actions
Impact
Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information.
Vulnerable versions
This security vulnerability is present in Ghost v4.46.0-v5.89.5.
Ghost(Pro) customers are automatically updated to fixed versions ahead of disclosure.
If you're a self-hoster, please follow our update instructions.
Patches
v5.89.5 contains a fix for this issue.
Workarounds
Disable site membership in Ghost settings.
For more information
If you have any questions or comments about this advisory:
Email us at security@ghost.org
Other sources
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43409?
CVE-2024-43409 has been assessed as a moderate severity vulnerability due to improper authentication that may lead to unauthorized access to member actions.
How do I fix CVE-2024-43409?
To fix CVE-2024-43409, upgrade to Ghost version 5.89.6 or later, or to version 2.39.1 of the @tryghost/portal package.
What versions are affected by CVE-2024-43409?
CVE-2024-43409 affects Ghost versions from 4.46.0 to 5.89.5 and @tryghost/portal versions from 1.22.2 to 2.39.0.
What actions can an attacker perform due to CVE-2024-43409?
An attacker exploiting CVE-2024-43409 can perform member-only actions and access sensitive member information.
Is CVE-2024-43409 exploitable remotely?
Yes, CVE-2024-43409 can be exploited remotely due to improper authentication on specific endpoints.