CRITICAL
Improper Input Validation in publify/publify
Published Jan 14, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.91%
Description
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10.
Affected products
-
Affected
- ≥ unspecified, < 9.2.10
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Publify | Publify/publify | unknown | Affected
|
- < 9.2.10
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0526 Advisory
- https://github.com/advisories/GHSA-q3rm-f527-ghxj Advisory
- https://github.com/publify/publify/commit/ca46da283572b4f8c0b5aa245008756c8a5fd1b1 PatchThird Party Advisory
- https://github.com/publify/publify_core/commit/34f6e9c98e0e3b3f9896f9676b3d6442220e2b4e
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/publify_core/CVE-2023-0299.yml
- https://huntr.dev/bounties/0049774b-1857-46dc-a834-f1fb15138c53 ExploitPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-0299
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Jan 14, 2023
Updated Apr 7, 2025
Reserved Jan 14, 2023
Link CVE-2023-0299
CISA Vulnrichment
Updated Apr 7, 2025
Red Hat
No data
GitHub
Link GHSA-Q3RM-F527-GHXJ