Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being shared between different visitors, an unauthenticated user could send an x-ghost-preview header that altered the rendered frontend response. In affected cache configurations, that response could be stored and served to subsequent visitors requesting the same page, allowing cache poisoning of request-specific preview output. When running Ghost's frontend and admin panel on the same domain this could be used to take over staff user accounts. When running these on different domains staff accounts have no exposure. This vulnerability is fixed in 6.37.0.
When Ghost runs behind a shared cache layer, an attacker can send a crafted x-ghost-preview header that modifies the rendered frontend response. The modified response can be stored in the cache and subsequently served to subsequent users visiting the same page. In a configuration where Ghost frontend and admin panel run on the same domain, this mechanism can be exploited to take over staff accounts.
An attacker can poison the service cache and serve malicious content to unsuspecting users, and in a specific domain configuration can take over Ghost CMS staff user accounts.
Ghost CMS should be updated to version 6.37.0 or newer, where the vulnerability has been fixed. As a workaround, running the frontend and admin panel on separate domains eliminates the risk of staff account takeover.
Ghost CMS in versions below 6.37.0, running behind a shared cache layer; account takeover vulnerability applies only to configurations where frontend and admin panel are served on the same domain
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H