{"id":"CVE-2021-39192","details":"Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authenticated users (including contributors) to view admin-level API keys via the integrations API endpoint, leading to a privilege escalation vulnerability. This issue is patched in Ghost version 4.10.0. As a workaround, disable all non-Administrator accounts to prevent API access. It is highly recommended to regenerate all API keys after patching or applying the workaround.","aliases":["BIT-ghost-2021-39192","GHSA-j5c2-hm46-wp5c"],"modified":"2026-08-07T19:46:49.309350Z","published":"2021-09-03T15:15:09.410Z","references":[{"type":"ADVISORY","url":"https://github.com/TryGhost/Ghost/releases/tag/v4.10.0"},{"type":"ADVISORY","url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-j5c2-hm46-wp5c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tryghost/ghost","events":[{"introduced":"6058ee39069f83c698cc0c8d4492a4dfd2c4eed2"},{"fixed":"62d31bc65d92e2893358abc9e01f0b02fb31ae00"}],"database_specific":{"cpe":"cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.10.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v4.9.1","v4.9.0","v4.8.0","v4.7.0","v4.6.2","v4.6.1","v4.6.0","v4.5.0","v4.4.0","v4.3.0","v4.2.0","v4.1.2","v4.1.1","v4.1.0","v4.0.1","v4.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-39192.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}