Web: https://blog.talosintelligence.com/vulnerability-spotlight-node-sqlite3-issue-could-lead-to-denial-of-service-in-ghost-cms/

March 16, 2023, 6:32 p.m. | Jonathan Munshaw

Cisco Talos Intelligence Group - Comprehensive Threat Intelligence blog.talosintelligence.com

Due to JSON format limitations, the vulnerability only manifests itself as a remote denial of service in Ghost CMS, which crashes the Node.js process. However, the vulnerability could potentially lead to remote code execution in other products that use it.

cms denial of service ghost node service spotlight sqlite3 vulnerability vulnerability spotlight

Senior Consultant in Procurement

@ Sia Partners | Antwerp, Belgium

SOC Security Analyst, Tier 2

@ Cybereason | Tokyo

Host Based Systems Analyst 4/Threat Hunter

@ ARSIEM | Arlington, VA

Director, Client Solutions - Cybersecurity - East Enterprise

@ Optiv | Charlotte, NC

Cyber Program Manager

@ XOR Security | Washington, DC

Strategic Insights Consultant

@ NielsenIQ | Oxford, United Kingdom

Software Engineer - Sr. Consultant Level-Applied Cryptography Software Development

@ Visa | Bengaluru, India

Security Lead

@ Shopify | Boston, MA, United States

Ingénieur Gouvernance Cybersécurité

@ Alter Solutions | Paris, France

Senior Software Engineer, Security

@ Duolingo | Pittsburgh, PA

IT SOX Audit and Compliance Analyst

@ Western Digital | Bengaluru, India

Chief Information Security Officer - CISO (m/f/d)

@ SoSafe | Remote