Vulnerabilities
Vulnerable Software
Ghost:  >> Ghost  >> 5.85.0  Security Vulnerabilities
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-08-20
Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.
CVSS Score
9.1
EPSS Score
0.004
Published
2024-06-16


Contact Us

Shodan ® - All rights reserved