Impact
Ghost from version 0.7.2 before 6.64.0 has an information disclosure flaw in its Admin API that allows authenticated staff users to infer the relative ordering of password hashes of other staff members. While this does not reveal actual hash values, it gives attackers a measurable advantage when attempting brute‑force or dictionary attacks. The weakness is classified as CWE‑203.
Affected Systems
TryGhost Ghost installations running any version from 0.7.2 up through 6.63.x, inclusive, are affected. The issue exists in the public GitHub releases and is referenced in GitHub Advisory GHSA‑53vv‑xm9f‑mm82. Staff or other authenticated users with Admin API permissions can exploit it.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited exploitation momentum. Nevertheless, because the relative ordering may reduce the effort required for a password‑cracking campaign, organizations should treat it as a low‑risk, but actionable, disclosure that can be mitigated by upgrading or restricting Admin API access.
OpenCVE Enrichment