CRITICAL9.8
GHSA-q3rm-f527-ghxj
Publify Improper Input Validation vulnerability
Quick fix
GHSA-q3rm-f527-ghxj — publify_core: upgrade to the fixed version with the command below.
bundle update publify_coreDetails
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-0299[ADVISORY]
- https://github.com/publify/publify/commit/ca46da283572b4f8c0b5aa245008756c8a5fd1b1[WEB]
- https://github.com/publify/publify_core/commit/34f6e9c98e0e3b3f9896f9676b3d6442220e2b4e[WEB]
- https://github.com/publify/publify[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/publify_core/CVE-2023-0299.yml[WEB]
- https://huntr.dev/bounties/0049774b-1857-46dc-a834-f1fb15138c53[WEB]