Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-3590

Опубликовано: 14 дек. 2022
Источник: debian
EPSS Низкий

Описание

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wordpressunfixedpackage
wordpresspostponedtrixiepackage
wordpresspostponedbookwormpackage
wordpressno-dsabullseyepackage
wordpresspostponedbusterpackage

Примечания

  • https://www.sonarsource.com/blog/wordpress-core-unauthenticated-blind-ssrf/

EPSS

Процентиль: 87%
0.0315
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 4 года назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
nvd
почти 4 года назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
github
почти 4 года назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
fstec
больше 9 лет назад

Уязвимость метода pingback.ping системы управления содержимым сайта WordPress, позволяющая нарушителю осуществить SSRF-атаку

EPSS

Процентиль: 87%
0.0315
Низкий