Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5hr6-r8h6-wh22

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

JetPack Exposure of Resource to Wrong Sphere

The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked.

Пакеты

Наименование

automattic/jetpack

composer
Затронутые версииВерсия исправления

< 9.8

9.8

EPSS

Процентиль: 73%
0.00789
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284
CWE-639
CWE-668

Связанные уязвимости

CVSS3: 5.3
nvd
больше 4 лет назад

The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked.

EPSS

Процентиль: 73%
0.00789
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284
CWE-639
CWE-668