Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mjj5-7gmf-mfjx

Опубликовано: 14 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

EPSS

Процентиль: 95%
0.20796
Средний

5.9 Medium

CVSS3

Дефекты

CWE-367
CWE-918

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
nvd
больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
debian
больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback ...

EPSS

Процентиль: 95%
0.20796
Средний

5.9 Medium

CVSS3

Дефекты

CWE-367
CWE-918