Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-3590

Опубликовано: 14 дек. 2022
Источник: debian
EPSS Средний

Описание

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wordpressunfixedpackage
wordpresspostponedtrixiepackage
wordpresspostponedbookwormpackage
wordpressno-dsabullseyepackage
wordpresspostponedbusterpackage

Примечания

  • https://www.sonarsource.com/blog/wordpress-core-unauthenticated-blind-ssrf/

EPSS

Процентиль: 95%
0.20796
Средний

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
nvd
больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
github
больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

EPSS

Процентиль: 95%
0.20796
Средний