Description
Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3.
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
6.0.0 (custom)
5.99.0 (custom)
References
fluidattacks.com/advisories/regida
fluidattacks.com/advisories/regida
github.com/TryGhost/Ghost
github.com/TryGhost/Ghost/releases/tag/v6.0.9
github.com/.../Ghost/security/advisories/GHSA-f7qg-xj45-w956