VDB
Sign up
MEDIUM4.9

GHSA-5jm7-g527-m694

Publify exposes article metadata

Quick fix

GHSA-5jm7-g527-m694 — publify_core: upgrade to the fixed version with the command below.

bundle update publify_core

Details

Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/publify_core
Introduced in: 0Fixed in: 9.2.8
Fixbundle update publify_core

References