Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE0aDgtN3FmZi1naDZj

Server-side request forgery in Ghost CMS

Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal systems.

Permalink: https://github.com/advisories/GHSA-q4h8-7qff-gh6c
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE0aDgtN3FmZi1naDZj
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 3 years ago
Updated: over 1 year ago


CVSS Score: 8.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Identifiers: GHSA-q4h8-7qff-gh6c, CVE-2020-8134
References: Blast Radius: 21.6

Affected Packages

npm:ghost
Dependent packages: 8
Dependent repositories: 468
Downloads: 59,281 last month
Affected Version Ranges: < 3.10.0
Fixed in: 3.10.0
All affected versions: 0.4.2, 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5, 0.5.6, 0.5.7, 0.5.8, 0.5.9, 0.5.10, 0.6.0, 0.6.1, 0.6.2, 0.6.3, 0.6.4, 0.7.0, 0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.7.5, 0.7.6, 0.7.7, 0.7.8, 0.7.9, 0.8.0, 0.9.0, 0.10.1, 0.11.0, 0.11.1, 0.11.2, 0.11.3, 0.11.4, 0.11.5, 0.11.6, 0.11.7, 0.11.8, 0.11.9, 0.11.10, 0.11.11, 0.11.12, 0.11.13, 0.11.14, 1.0.0, 1.0.2, 1.1.0, 1.2.0, 1.3.0, 1.4.0, 1.5.0, 1.5.1, 1.5.2, 1.6.0, 1.6.1, 1.6.2, 1.7.0, 1.7.1, 1.8.0, 1.8.1, 1.8.2, 1.8.3, 1.8.4, 1.8.5, 1.8.6, 1.8.7, 1.9.0, 1.9.1, 1.10.0, 1.11.0, 1.11.1, 1.12.0, 1.12.1, 1.13.0, 1.14.0, 1.14.1, 1.15.0, 1.15.1, 1.16.0, 1.16.1, 1.16.2, 1.17.0, 1.17.1, 1.17.2, 1.17.3, 1.18.0, 1.18.1, 1.18.2, 1.18.3, 1.18.4, 1.19.0, 1.19.1, 1.19.2, 1.20.0, 1.20.1, 1.20.2, 1.20.3, 1.21.0, 1.21.1, 1.21.2, 1.21.3, 1.21.4, 1.21.5, 1.21.6, 1.21.7, 1.22.0, 1.22.1, 1.22.2, 1.22.3, 1.22.4, 1.22.5, 1.22.6, 1.22.7, 1.22.8, 1.23.0, 1.23.1, 1.24.0, 1.24.1, 1.24.2, 1.24.3, 1.24.4, 1.24.5, 1.24.6, 1.24.7, 1.24.8, 1.24.9, 1.25.0, 1.25.1, 1.25.2, 1.25.3, 1.25.4, 1.25.5, 1.25.6, 1.25.7, 1.25.8, 1.26.0, 1.26.1, 1.26.2, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.2.0, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.3.0, 2.4.0, 2.5.0, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, 2.8.0, 2.9.0, 2.9.1, 2.10.0, 2.10.1, 2.10.2, 2.11.0, 2.11.1, 2.12.0, 2.13.0, 2.13.1, 2.13.2, 2.14.0, 2.14.1, 2.14.2, 2.14.3, 2.15.0, 2.16.0, 2.16.1, 2.16.2, 2.16.3, 2.16.4, 2.17.0, 2.17.1, 2.17.2, 2.18.0, 2.18.1, 2.18.2, 2.18.3, 2.19.0, 2.19.1, 2.19.2, 2.19.3, 2.19.4, 2.20.0, 2.20.1, 2.21.0, 2.21.1, 2.22.0, 2.22.1, 2.22.2, 2.22.3, 2.23.0, 2.23.1, 2.23.2, 2.23.3, 2.23.4, 2.25.0, 2.25.1, 2.25.2, 2.25.3, 2.25.4, 2.25.5, 2.25.6, 2.25.7, 2.25.8, 2.25.9, 2.26.0, 2.27.0, 2.28.0, 2.28.1, 2.29.0, 2.29.1, 2.30.0, 2.30.1, 2.30.2, 2.31.0, 2.31.1, 2.32.0, 2.33.0, 2.34.0, 2.35.0, 2.36.0, 2.37.0, 2.37.1, 2.37.2, 2.38.0, 2.38.1, 2.38.2, 2.38.3, 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.1.0, 3.1.1, 3.2.0, 3.3.0, 3.4.0, 3.5.0, 3.5.1, 3.5.2, 3.6.0, 3.7.0, 3.8.0, 3.9.0
All unaffected versions: 3.10.0, 3.11.0, 3.12.0, 3.12.1, 3.13.0, 3.13.1, 3.13.2, 3.13.3, 3.13.4, 3.14.0, 3.15.0, 3.15.1, 3.15.2, 3.15.3, 3.16.0, 3.16.1, 3.17.0, 3.17.1, 3.18.0, 3.18.1, 3.19.0, 3.19.1, 3.19.2, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.21.1, 3.22.0, 3.22.1, 3.22.2, 3.23.0, 3.23.1, 3.24.0, 3.25.0, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.29.0, 3.29.1, 3.29.2, 3.30.0, 3.30.1, 3.30.2, 3.31.0, 3.31.1, 3.31.2, 3.31.3, 3.31.4, 3.31.5, 3.32.1, 3.32.2, 3.33.0, 3.34.0, 3.34.1, 3.35.0, 3.35.1, 3.35.2, 3.35.3, 3.35.4, 3.35.5, 3.36.0, 3.37.0, 3.37.1, 3.38.0, 3.38.1, 3.38.2, 3.38.3, 3.39.0, 3.39.1, 3.39.2, 3.39.3, 3.40.0, 3.40.1, 3.40.2, 3.40.3, 3.40.4, 3.40.5, 3.41.0, 3.41.1, 3.41.2, 3.41.3, 3.41.4, 3.41.5, 3.41.6, 3.41.7, 3.41.8, 3.41.9, 3.42.0, 3.42.1, 3.42.2, 3.42.3, 3.42.4, 3.42.5, 3.42.6, 3.42.7, 3.42.8, 3.42.9, 4.0.0, 4.0.1, 4.1.0, 4.1.1, 4.1.2, 4.2.0, 4.2.1, 4.2.2, 4.3.0, 4.3.1, 4.3.2, 4.3.3, 4.4.0, 4.5.0, 4.6.0, 4.6.1, 4.6.2, 4.6.3, 4.6.4, 4.6.5, 4.6.6, 4.7.0, 4.8.0, 4.8.1, 4.8.2, 4.8.3, 4.8.4, 4.9.0, 4.9.1, 4.9.2, 4.9.3, 4.9.4, 4.10.0, 4.10.1, 4.10.2, 4.11.0, 4.12.0, 4.12.1, 4.13.0, 4.14.0, 4.15.0, 4.15.1, 4.16.0, 4.17.0, 4.17.1, 4.18.0, 4.19.0, 4.19.1, 4.20.0, 4.20.1, 4.20.2, 4.20.3, 4.20.4, 4.21.0, 4.22.0, 4.22.1, 4.22.2, 4.22.3, 4.22.4, 4.23.0, 4.24.0, 4.25.0, 4.25.1, 4.26.0, 4.26.1, 4.27.0, 4.27.1, 4.27.2, 4.28.0, 4.29.0, 4.30.0, 4.30.1, 4.31.0, 4.32.0, 4.32.1, 4.32.2, 4.32.3, 4.33.0, 4.33.1, 4.33.2, 4.34.0, 4.34.1, 4.34.2, 4.34.3, 4.35.0, 4.36.0, 4.36.1, 4.36.2, 4.36.3, 4.37.0, 4.38.0, 4.38.1, 4.39.0, 4.39.1, 4.40.0, 4.41.0, 4.41.1, 4.41.2, 4.41.3, 4.42.0, 4.42.1, 4.43.0, 4.43.1, 4.44.0, 4.45.0, 4.46.0, 4.46.1, 4.46.2, 4.47.0, 4.47.1, 4.47.2, 4.47.3, 4.47.4, 4.48.0, 4.48.1, 4.48.2, 4.48.3, 4.48.4, 4.48.5, 4.48.6, 4.48.7, 4.48.8, 4.48.9, 5.0.0, 5.0.1, 5.0.2, 5.1.0, 5.1.1, 5.2.0, 5.2.1, 5.2.2, 5.2.3, 5.2.4, 5.3.0, 5.3.1, 5.4.0, 5.4.1, 5.5.0, 5.6.0, 5.7.0, 5.7.1, 5.8.0, 5.8.1, 5.8.2, 5.8.3, 5.9.0, 5.9.1, 5.9.2, 5.9.3, 5.9.4, 5.10.0, 5.10.1, 5.11.0, 5.12.0, 5.12.1, 5.12.2, 5.12.3, 5.12.4, 5.13.0, 5.13.1, 5.13.2, 5.14.0, 5.14.1, 5.14.2, 5.15.0, 5.16.0, 5.16.1, 5.16.2, 5.17.0, 5.17.1, 5.17.2, 5.18.0, 5.19.0, 5.19.1, 5.19.2, 5.19.3, 5.20.0, 5.21.0, 5.22.0, 5.22.1, 5.22.2, 5.22.3, 5.22.4, 5.22.5, 5.22.6, 5.22.7, 5.22.8, 5.22.9, 5.22.10, 5.22.11, 5.23.0, 5.24.0, 5.24.1, 5.24.2, 5.25.0, 5.25.1, 5.25.2, 5.25.3, 5.25.4, 5.25.5, 5.26.0, 5.26.1, 5.26.2, 5.26.3, 5.26.4, 5.27.0, 5.28.0, 5.29.0, 5.30.0, 5.30.1, 5.31.0, 5.32.0, 5.33.0, 5.33.1, 5.33.2, 5.33.3, 5.33.4, 5.33.5, 5.33.6, 5.33.7, 5.33.8, 5.34.0, 5.34.1, 5.35.0, 5.35.1, 5.36.0, 5.36.1, 5.37.0, 5.38.0, 5.39.0, 5.40.0, 5.40.1, 5.40.2, 5.41.0, 5.42.0, 5.42.1, 5.42.2, 5.42.3, 5.43.0, 5.44.0, 5.45.0, 5.45.1, 5.46.0, 5.46.1, 5.47.0, 5.47.1, 5.47.2, 5.48.0, 5.48.1, 5.49.0, 5.49.1, 5.49.2, 5.49.3, 5.50.0, 5.50.1, 5.50.2, 5.50.3, 5.50.4, 5.51.0, 5.51.1, 5.51.2, 5.52.0, 5.52.1, 5.52.2, 5.52.3, 5.53.0, 5.53.1, 5.53.2, 5.53.3, 5.53.4, 5.54.0, 5.54.1, 5.54.2, 5.54.3, 5.54.4, 5.55.0, 5.55.1, 5.55.2, 5.56.0, 5.56.1, 5.57.0, 5.57.1, 5.57.2, 5.57.3, 5.58.0, 5.59.0, 5.59.1, 5.59.2, 5.59.3, 5.59.4, 5.60.0, 5.61.0, 5.61.1, 5.61.2, 5.61.3, 5.62.0, 5.63.0, 5.64.0, 5.65.0, 5.65.1, 5.66.0, 5.66.1, 5.67.0, 5.68.0, 5.69.0, 5.69.1, 5.69.2, 5.69.3, 5.69.4, 5.70.0, 5.70.1, 5.70.2, 5.71.0, 5.71.1, 5.71.2, 5.72.0, 5.72.1, 5.72.2, 5.73.0, 5.73.1, 5.73.2, 5.74.0, 5.74.1, 5.74.2, 5.74.3, 5.74.4, 5.74.5, 5.75.0, 5.75.1, 5.75.2, 5.75.3, 5.76.0, 5.76.1, 5.76.2, 5.77.0, 5.78.0, 5.79.0, 5.79.1, 5.79.3, 5.79.4, 5.79.5, 5.79.6, 5.80.0, 5.80.1, 5.80.2, 5.80.3, 5.80.4, 5.80.5, 5.81.0, 5.81.1, 5.82.0, 5.82.1, 5.82.2, 5.82.3, 5.82.4, 5.82.5, 5.82.6, 5.82.7, 5.82.8, 5.82.9, 5.82.10, 5.82.11, 5.82.12, 5.83.0, 5.84.0, 5.84.1, 5.84.2, 5.85.0, 5.85.1, 5.85.2, 5.86.0, 5.86.1, 5.86.2, 5.87.0, 5.87.1