{"id":"GHSA-x3rq-r3cm-5vc4","summary":"Publify Business Logic Errors","details":"Publify (formerly known as Typo) prior to version 9.2.7 is vulnerable to business logic errors.","aliases":["BIT-publify-2022-0524","CVE-2022-0524"],"modified":"2024-02-15T05:25:02.340273Z","published":"2022-02-09T00:00:27Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-02-09T18:33:00Z","nvd_published_at":"2022-02-08T22:15:00Z","cwe_ids":["CWE-841"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0524"},{"type":"WEB","url":"https://github.com/publify/publify/pull/1044"},{"type":"WEB","url":"https://github.com/publify/publify/commit/16fceecadbe80ab0ef846b62a12dc7bfff10b8c5"},{"type":"WEB","url":"https://github.com/publify/publify"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/publify_core/CVE-2022-0524.yml"},{"type":"WEB","url":"https://huntr.dev/bounties/bfffae58-b3cd-4e0e-b1f2-3db387a22c3d"}],"affected":[{"package":{"name":"publify_core","ecosystem":"RubyGems","purl":"pkg:gem/publify_core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.2.7"}]}],"versions":["9.0.0","9.0.0.pre1","9.0.0.pre2","9.0.0.pre3","9.0.0.pre4","9.0.0.pre5","9.0.0.pre6","9.0.1","9.1.0","9.2.0","9.2.1","9.2.2","9.2.3","9.2.4","9.2.5","9.2.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-x3rq-r3cm-5vc4/GHSA-x3rq-r3cm-5vc4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}