{"id":"GHSA-j5c2-hm46-wp5c","summary":"Privilege escalation: all users can access Admin-level API keys","details":"### Impact\nAn error in the implementation of the limits service in 4.0.0 allows all authenticated users (including contributors) to view admin-level API keys via the integrations API endpoint, leading to a privilege escalation vulnerability.\n\nGhost(Pro) has already been patched. Self-hosters are impacted if running Ghost a version between 4.0.0 and 4.9.4. Immediate action should be taken to secure your site - see patches & workarounds below.\n\nIt is highly recommended to regenerate all API keys after patching or applying the workaround below.\n\n### Patches\nFixed in 4.10.0, all 4.x sites should upgrade as soon as possible.\n\n### Workarounds\n- Disable all non-Administrator accounts to prevent API access.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* email us at security@ghost.org\n\n---\nCredits: Aden Yap Chuen Zhen, BAE Systems Applied Intelligence (Malaysia)","aliases":["BIT-ghost-2021-39192","CVE-2021-39192"],"modified":"2026-07-08T06:29:28.174243385Z","published":"2021-07-22T19:43:16Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-07-20T17:44:30Z","nvd_published_at":"2021-09-03T15:15:00Z","cwe_ids":["CWE-200","CWE-269"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-j5c2-hm46-wp5c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-39192"},{"type":"PACKAGE","url":"https://github.com/TryGhost/Ghost"},{"type":"WEB","url":"https://github.com/TryGhost/Ghost/releases/tag/v4.10.0"}],"affected":[{"package":{"name":"ghost","ecosystem":"npm","purl":"pkg:npm/ghost"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.10.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/07/GHSA-j5c2-hm46-wp5c/GHSA-j5c2-hm46-wp5c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"}]}