HIGH7.5
GHSA-x3rq-r3cm-5vc4
Publify Business Logic Errors
Quick fix
GHSA-x3rq-r3cm-5vc4 — publify_core: upgrade to the fixed version with the command below.
bundle update publify_coreDetails
Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-0524[ADVISORY]
- https://github.com/publify/publify/pull/1044[WEB]
- https://github.com/publify/publify/commit/16fceecadbe80ab0ef846b62a12dc7bfff10b8c5[WEB]
- https://github.com/publify/publify[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/publify_core/CVE-2022-0524.yml[WEB]
- https://huntr.dev/bounties/bfffae58-b3cd-4e0e-b1f2-3db387a22c3d[WEB]