Junglewise Threat Intelligence

CVE-2021-39192: Ghost privilege escalation in integrations API

CVE-2021-39192 · Severity: low · CVSS 3.1 · Published 2021-07-22

Technologies: ghost (npm). Vendors: npm, Ghost.

Executive brief

Ghost is a popular open-source publishing platform used for blogs and content management. A flaw in its API access control allows regular contributors and lower-privileged users to retrieve admin-level API keys through the integrations endpoint. An attacker with any authenticated account can access sensitive keys used to integrate third-party services, potentially leading to unauthorized access to connected systems and data exposure.

Technical details

The vulnerability is an authorization bypass (CWE-269) in Ghost versions 4.0.0 through 4.9.4, caused by an error in the limits service implementation. Authenticated users (including contributors) can call the integrations API endpoint to retrieve admin-level API keys, which should only be accessible to administrators. The attack requires valid user credentials but no additional user interaction; the flaw affects the API endpoint's permission checks. An attacker can read sensitive API keys that grant administrative privileges. The vulnerability was fixed in version 4.10.0; all affected self-hosted instances should upgrade immediately and regenerate all API keys.

Affected products

  • Ghost Ghost 4.0.0 to 4.9.4

Timeline

  • 2021-07-22: disclosed
  • 2021-07-20: patched: Fixed in version 4.10.0

References

Related threats