VDB
Sign up
MEDIUM6.5

GHSA-78x2-cwp9-5j42

Ghost's improper authentication allows access to member information and actions

Quick fix

GHSA-78x2-cwp9-5j42 — ghost: upgrade to the fixed version with the command below.

npm install ghost@5.89.5

Details

### Impact

Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information.

### Vulnerable versions

This security vulnerability is present in Ghost v4.46.0-v5.89.5.

Ghost(Pro) customers are automatically updated to fixed versions ahead of disclosure.

If you're a self-hoster, please follow our [update instructions](https://ghost.org/docs/update).

### Patches

v5.89.5 contains a fix for this issue.

### Workarounds

Disable site membership in Ghost settings.

### For more information

If you have any questions or comments about this advisory:

* Email us at [security@ghost.org](mailto:security@ghost.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ghost
Introduced in: 4.46.0Fixed in: 5.89.5
Fixnpm install ghost@5.89.5
npm/@tryghost/portal
Introduced in: 1.22.2Fixed in: 2.39.0
Fixnpm install @tryghost/portal@2.39.0

References