Junglewise Threat Intelligence

CVE-2022-41654: Ghost unauthorized newsletter modification via improper access control

CVE-2022-41654 · Severity: low · CVSS 3.1 · Published 2022-11-28

Vendors: Ghost.

Executive brief

Ghost is a popular blogging and content management platform. An improper access control vulnerability allows unprivileged member users to view and modify newsletter settings they should not have access to. While this does not grant permanent privilege escalation or broad data access, it undermines the integrity of newsletter administration and could be exploited to alter newsletter configuration or settings.

Technical details

A gap in Ghost's API validation for nested objects allows unprivileged members to bypass access controls on the newsletter modification endpoint. The vulnerability is rooted in CWE-284 (Improper Access Control) and stems from insufficient validation when processing nested request objects. Exploitation requires low privileges (an authenticated member account) and network reachability to the Ghost API; no user interaction is required. Successful exploitation enables reading and modifying newsletter settings that should be restricted to administrators. Patches are available in v4.48.8, v5.22.7, and later releases; deeper API-level fixes were included in v4.48.9 and v5.24.1.

Affected products

  • Ghost Ghost 4.46.0 to 4.48.7, 5.0.0 to 5.22.6

Timeline

  • 2022-11-28: disclosed
  • 2022-11-28: patched: Patches v4.48.8 and v5.22.7 available; v4.48.9 and v5.24.1 contain deeper fixes

References