Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-3590

Опубликовано: 14 дек. 2022
Источник: debian

Описание

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wordpressunfixedpackage
wordpresspostponedtrixiepackage
wordpresspostponedbookwormpackage
wordpressno-dsabullseyepackage
wordpresspostponedbusterpackage

Примечания

  • https://www.sonarsource.com/blog/wordpress-core-unauthenticated-blind-ssrf/

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 3 года назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
nvd
почти 3 года назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
github
почти 3 года назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.