MEDIUM6.5
GHSA-x24j-87x9-jvv5
Publify `guest` role users can self-register even when the admin does not allow it
Quick fix
GHSA-x24j-87x9-jvv5 — publify_core: upgrade to the fixed version with the command below.
bundle update publify_coreDetails
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. `guest` role users can self-register even when the admin does not allow it. This happens due to front-end restriction only.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-25973[ADVISORY]
- https://github.com/publify/publify/commit/3447e0241e921b65f6eb1090453d8ea73e98387e[WEB]
- https://github.com/publify/publify[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/publify_core/CVE-2021-25973.yml[WEB]
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25973[WEB]