{"id":"CVE-2022-2815","aliases":["BIT-publify-2022-2815","GHSA-79wq-g4v9-gfj4"],"url":"https://o3.security/vulnerability/CVE-2022-2815","summary":"Insecure Storage of Sensitive Information in publify/publify","details":"Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10.","published":"2023-01-14T00:00:00Z","modified":"2026-08-12T03:51:35.532408603Z","cvss":{"score":4.6,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"},"epss":{"score":0.00562,"percentile":0.44979,"asOf":"2026-09-11"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"publify_core","fixedVersion":"9.2.10"}],"fix":{"url":"https://github.com/publify/publify/commit/af69097d349f4c00f244c51cd3c3e937fd3387cd","label":"publify/publify@af69097"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/22fdcc39-8c1a-4e4c-8eae-be3fd764f8b4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2815.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-2815"},{"type":"FIX","url":"https://github.com/publify/publify/commit/af69097d349f4c00f244c51cd3c3e937fd3387cd"},{"type":"WEB","url":"https://github.com/publify/publify_core/commit/33f897c12b6efdcdfd8cf9df924deba0f878b71e"},{"type":"PACKAGE","url":"https://github.com/publify/publify"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/publify_core/CVE-2022-2815.yml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:35.532408603Z"}}