Description
Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal systems.
Remediation
References
https://hackerone.com/reports/793704
Related Vulnerabilities
CVE-2017-16121 Vulnerability in npm package datachannel-client
CVE-2019-6283 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2022-0624 Vulnerability in npm package parse-path
CVE-2023-26129 Vulnerability in npm package bwm-ng
CVE-2021-43138 Vulnerability in maven package org.webjars:async