MEDIUM6.5
GHSA-g7gf-2rqw-5rwx
Publify contains Weak Password Requirements
Quick fix
GHSA-g7gf-2rqw-5rwx — publify_core: upgrade to the fixed version with the command below.
bundle update publify_coreDetails
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-0569[ADVISORY]
- https://github.com/publify/publify/commit/8905e4e639cf03b758da558568a86c9816253b2d[WEB]
- https://github.com/publify/publify[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/publify_core/CVE-2023-0569.yml[WEB]
- https://huntr.dev/bounties/81b1e1da-10dd-435e-94ae-4bdd41df6df9[WEB]