Description
Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or member data or stealing money from a site or its members. This issue is fixed in version 6.44.0.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Affected products
- TryGhost / Ghost>= 6.27.0, < 6.44.0 – >= 6.27.0, < 6.44.0
References
- VENDOR_ADVISORYhttps://github.com/TryGhost/Ghost/security/advisories/GHSA-xm43-3m56-w3wf
- PATCHhttps://github.com/TryGhost/Ghost/pull/28351
- PATCHhttps://github.com/TryGhost/Ghost/pull/28352
- PATCHhttps://github.com/TryGhost/Ghost/commit/cab716cd015ac04b7ee50c7a405478d97bc7b1e0
- PATCHhttps://github.com/TryGhost/Ghost/commit/ee7b991b466a7849c70f9d1caed8e491ee4113c6
Updated 5m ago · 8 sources