We found results for “”
WS-2016-7128
Date: November 8, 2016
Overview
Ghost CMS v0.8.0 and v0.9.0 are vulnerable to denial of serviceDetails
Ghost CMS v0.8.0 and v0.9.0 are vulnerable to denial of service when attempting to parse invalid uploaded file as CSV.Affected Environments
Ghost CMS v0.8.0 and v0.9.0Prevention
Upgrade to Ghost CMS version 0.10.0Language: JS
Good to know:
Base Score: |
|
---|---|
Attack Vector (AV): | Network |
Attack Complexity (AC): | Low |
Privileges Required (PR): | Low |
User Interaction (UI): | None |
Scope (S): | Unchanged |
Confidentiality (C): | None |
Integrity (I): | None |
Availability (A): | Low |