VDB
Sign up
HIGH7.5

GHSA-r97q-ghch-82j9

Ghost vulnerable to information disclosure of private API fields

Quick fix

GHSA-r97q-ghch-82j9 — ghost: upgrade to the fixed version with the command below.

npm install ghost@5.46.1

Details

### Impact

Due to a lack of validation when filtering on the public API endpoints, it is possible to reveal private fields via a brute force attack.

Ghost(Pro) has already been patched. We can find no evidence that the issue was exploited on Ghost(Pro) prior to the patch being added.

Self-hosters are impacted if running Ghost a version below v5.46.1. Immediate action should be taken to secure your site - see patches and workarounds below.

### Patches

v5.46.1 contains a fix for this issue.

### Workarounds

Add a block for requests to `/ghost/api/content/*` where the `filter` query parameter contains `password` or `email`.

### For more information

If you have any questions or comments about this advisory:

* Email us at [security@ghost.org](mailto:security@ghost.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ghost
Introduced in: 0Fixed in: 5.46.1
Fixnpm install ghost@5.46.1

References