Junglewise Threat Intelligence

CVE-2023-40028: Ghost arbitrary file read via symlinks in content import

CVE-2023-40028 · Severity: low · CVSS 3.1 · Published 2023-08-15

Technologies: ghost (npm). Vendors: Ghost, npm.

Executive brief

Ghost is a popular content management platform used to build and manage websites and blogs. A vulnerability allows authenticated users to upload files that are symbolic links, which can be exploited to read arbitrary files from the server's operating system, potentially exposing sensitive configuration files, database credentials, or other confidential data.

Technical details

The vulnerability exists in Ghost's content import functionality, which fails to properly validate and sanitize uploaded files for symlinks. An authenticated attacker can upload files that are symbolic links pointing to arbitrary system files. When Ghost processes or serves these symlinked files, it follows the symlink and exposes the contents of the target file. The attack requires authentication (authenticated users only), but once a user account is compromised or a legitimate user is malicious, any file readable by the Ghost process can be extracted. The vulnerability was fixed in version 5.59.1.

Affected products

  • Ghost Ghost ≤ 5.59.0

Timeline

  • 2023-08-15: disclosed
  • 2023-08-15: patched: Patched in version 5.59.1

References

Related threats