MEDIUM6.5
GHSA-w78q-4w34-jrjx
Publify vulnerable to code injection
Quick fix
GHSA-w78q-4w34-jrjx — publify_core: upgrade to the fixed version with the command below.
bundle update publify_coreDetails
Code Injection in GitHub repository publify/publify prior to 9.2.8.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-0578[ADVISORY]
- https://github.com/publify/publify/commit/b50df050c593cc532b2c516792989bcfce2d73f7[WEB]
- https://github.com/publify/publify[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/publify_core/CVE-2022-0578.yml[WEB]
- https://huntr.dev/bounties/02c81928-eb47-476f-8000-e93dc796dbcc[WEB]