{"id":"BIT-publify-2022-1553","details":"Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users.","aliases":["CVE-2022-1553","GHSA-5jm7-g527-m694"],"modified":"2024-03-06T11:25:28.861Z","published":"2024-03-06T11:03:42.987Z","database_specific":{"cpes":["cpe:2.3:a:publify_project:publify:*:*:*:*:*:*:*:*"],"severity":"Medium"},"references":[{"type":"WEB","url":"https://github.com/publify/publify/commit/1a78f16f460847274265a12a9555b3524892d7db"},{"type":"WEB","url":"https://huntr.dev/bounties/b398e4c9-6cdf-4973-ad86-da796cde221f"}],"affected":[{"package":{"name":"publify","ecosystem":"Bitnami","purl":"pkg:bitnami/publify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"9.2.8"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/publify/BIT-publify-2022-1553.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.7.3"}