{"id":"CVE-2022-1553","aliases":["BIT-publify-2022-1553","GHSA-5jm7-g527-m694"],"url":"https://o3.security/vulnerability/CVE-2022-1553","summary":"Leaking password protected articles content due to improper access control in publify/publify","details":"Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users.","published":"2022-05-16T14:31:58Z","modified":"2026-08-12T03:51:30.171920829Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"publify_core","fixedVersion":"9.2.8"}],"fix":{"url":"https://github.com/publify/publify/commit/1a78f16f460847274265a12a9555b3524892d7db","label":"publify/publify@1a78f16"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/b398e4c9-6cdf-4973-ad86-da796cde221f"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1553.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1553"},{"type":"FIX","url":"https://github.com/publify/publify/commit/1a78f16f460847274265a12a9555b3524892d7db"},{"type":"WEB","url":"https://github.com/publify/publify"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/publify_core/CVE-2022-1553.yml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:30.171920829Z"}}