GHSA-5hr6-r8h6-wh22
Dashboard / Vulnerabilities / GHSA-5hr6-r8h6-wh22
Summary: JetPack Exposure of Resource to Wrong Sphere
Details: The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-24374, https://github.com/Automattic/jetpack-production, https://jetpack.com/2021/06/01/jetpack-9-8-engage-your-audience-with-wordpress-stories, https://wpscan.com/vulnerability/08a8a51c-49d3-4bce-b7e0-e365af1d8f33
Affected packages
Package
Name: automattic/jetpack
Purl: pkg:composer/automattic/jetpack
Affected ranges
Type: ECOSYSTEM
Events:
