What the vulnerability does
01Description
Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from n/a through 1.4.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from n/a through 1.4.0.
Explanation of Vulnerability in Simple Terms
Ghost versions up to 1.4.0 expose sensitive log data that an attacker can read over the network without authentication. The vulnerability stems from improper handling of log file access controls. An attacker can retrieve detailed application logs containing potentially sensitive information. Update to a version newer than 1.4.0 to remediate.
What an attacker can do
Read application logs containing sensitive information without logging in.
Potential impact on your site
Attackers can access logs that may contain passwords, API keys, or other sensitive data exposed in error messages.
Conditions required to exploit
Network access to the Ghost instance; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities