Retour à la veille

CVE-2026-103281

Publié : 1 octobre 2026
Modifié : 1 octobre 2026
Lien officiel NVD
Score CVSS
5.4
MEDIUM

Description détaillée

Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff accounts. An authenticated low-privilege staff user can read API keys returned by the Admin API, which are intended to be available only to higher-privileged users.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Références et Patchs