github.com
https://github.com/publify/publify CVE-2022-1810
MEDIUM
Authorization Bypass Through User-Controlled Key in publify/publify
Record summary
CVE-2022-1810 has a selected CVSS score of 4.3 (medium).
Description
Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
publify/publifyBrowse publify / publify/publify | CVE List | Before 9.2.9 | affected |
publify_coreBrowse RubyGems / publify_core | GitHub Advisory | Before 9.2.9 · Fixed in 9.2.9 | affected |
References
5github.com
https://github.com/publify/publify/commit/c0aba87844d1e47da50c0d99a3465164a4d244ce github.com
https://github.com/rubysec/ruby-advisory-db/blob/master/gems/publify_core/CVE-2022-1810.yml huntr.dev
https://huntr.dev/bounties/9b2d7579-032e-42da-b736-4b10a868eacb nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-1810