{"id":"GHSA-7v28-g2pq-ggg8","summary":"Ghost vulnerable to remote code execution in locale setting change","details":"### Impact\n\nA [vulnerability](https://www.cve.org/CVERecord?id=CVE-2022-24785) in an upstream library means an authenticated attacker can abuse locale input to execute arbitrary commands from a file that has previously been uploaded using the file upload functionality in the post editor.\n\n### Patches\n\nFixed in 5.2.3, all 5.x sites should update as soon as possible.\nFixed in 4.48.2, all 4.x sites should update as soon as possible.\n\n### Workarounds\n\nPatched versions of Ghost add validation to the locale input to prevent execution of arbitrary files. Updating Ghost is the quickest complete solution.\n\nAs a workaround, if for any reason you cannot update your Ghost instance, you can block the `POST /ghost/api/admin/settings/` endpoint, which will also disable updating settings for your site.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Email us at [security@ghost.org](mailto:security@ghost.org)\n\n### Credits\n\n* devx00 - https://twitter.com/devx00","modified":"2022-08-10T22:15:39Z","published":"2022-06-17T01:16:03Z","database_specific":{"github_reviewed_at":"2022-06-17T01:16:03Z","nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-7v28-g2pq-ggg8"},{"type":"PACKAGE","url":"https://github.com/TryGhost/Ghost"}],"affected":[{"package":{"name":"ghost","ecosystem":"npm","purl":"pkg:npm/ghost"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.48.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-7v28-g2pq-ggg8/GHSA-7v28-g2pq-ggg8.json"}},{"package":{"name":"ghost","ecosystem":"npm","purl":"pkg:npm/ghost"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.0.0"},{"fixed":"5.2.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-7v28-g2pq-ggg8/GHSA-7v28-g2pq-ggg8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L"}]}