MEDIUM6.5
GHSA-79m3-q3wh-c3qm
Publify Incorrect Authorization
Quick fix
GHSA-79m3-q3wh-c3qm — publify_core: upgrade to the fixed version with the command below.
bundle update publify_coreDetails
Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Anonymous users can't view but can leave comments on an article in draft mode.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-0574[ADVISORY]
- https://github.com/publify/publify/commit/0e6c66ac2002136517662399bca9d838c80d9739[WEB]
- https://github.com/publify/publify[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/publify_core/CVE-2022-0574.yml[WEB]
- https://huntr.dev/bounties/6f322c84-9e20-4df6-97e8-92bc271ede3f[WEB]