MEDIUM4.3
GHSA-c273-c6vg-4pv5
Publify has Improper Access Controls
Quick fix
GHSA-c273-c6vg-4pv5 — publify_core: upgrade to the fixed version with the command below.
bundle update publify_coreDetails
A low-privileged user can modify and delete admin articles by changing the value of the `article[id]` parameter prior to 9.2.9.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-1810[ADVISORY]
- https://github.com/publify/publify/commit/c0aba87844d1e47da50c0d99a3465164a4d244ce[WEB]
- https://github.com/publify/publify[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/publify_core/CVE-2022-1810.yml[WEB]
- https://huntr.dev/bounties/9b2d7579-032e-42da-b736-4b10a868eacb[WEB]