Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU52315
Risk: Low
CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: N/A
CWE-ID:
CWE-312 - Cleartext Storage of Sensitive Information
Exploit availability: No
DescriptionThe vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists in the way Ghost stores secret settings. A local user can view contents of application files and obtain secret settings.
Install updates from vendor's website.
Vulnerable software versionsGhost: 3.0.0 - 4.2.1
CPE2.3 External linkshttp://github.com/TryGhost/Ghost/releases/tag/v4.2.2
http://github.com/TryGhost/Ghost/releases/tag/3.42.5
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.