github.com
https://github.com/publify/publify CVE-2023-0299
CRITICAL
Improper Input Validation in publify/publify
Record summary
CVE-2023-0299 has a selected CVSS score of 9.8 (critical).
Description
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 7, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
publify/publifyBrowse publify / publify/publify | CVE List | Before 9.2.10 | affected |
publify_coreBrowse RubyGems / publify_core | GitHub Advisory | Before 9.2.10 · Fixed in 9.2.10 | affected |
References
6github.com
https://github.com/publify/publify/commit/ca46da283572b4f8c0b5aa245008756c8a5fd1b1 github.com
https://github.com/publify/publify_core/commit/34f6e9c98e0e3b3f9896f9676b3d6442220e2b4e github.com
https://github.com/rubysec/ruby-advisory-db/blob/master/gems/publify_core/CVE-2023-0299.yml huntr.dev
https://huntr.dev/bounties/0049774b-1857-46dc-a834-f1fb15138c53 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-0299