{"id":"GHSA-7v28-g2pq-ggg8","aliases":[],"url":"https://o3.security/vulnerability/GHSA-7v28-g2pq-ggg8","summary":"Ghost vulnerable to remote code execution in locale setting change","details":"### Impact\n\nA [vulnerability](https://www.cve.org/CVERecord?id=CVE-2022-24785) in an upstream library means an authenticated attacker can abuse locale input to execute arbitrary commands from a file that has previously been uploaded using the file upload functionality in the post editor.\n\n### Patches\n\nFixed in 5.2.3, all 5.x sites should update as soon as possible.\nFixed in 4.48.2, all 4.x sites should update as soon as possible.\n\n### Workarounds\n\nPatched versions of Ghost add validation to the locale input to prevent execution of arbitrary files. Updating Ghost is the quickest complete solution.\n\nAs a workaround, if for any reason you cannot update your Ghost instance, you can block the `POST /ghost/api/admin/settings/` endpoint, which will also disable updating settings for your site.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Email us at [security@ghost.org](mailto:security@ghost.org)\n\n### Credits\n\n* devx00 - https://twitter.com/devx00","published":"2022-06-17T01:16:03Z","modified":"2022-08-10T22:15:39Z","cvss":{"score":6.6,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"ghost","fixedVersion":"4.48.2"},{"ecosystem":"npm","name":"ghost","fixedVersion":"5.2.3"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-7v28-g2pq-ggg8"},{"type":"PACKAGE","url":"https://github.com/TryGhost/Ghost"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2022-08-10T22:15:39Z"}}