Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3590

Опубликовано: 14 дек. 2022
Источник: nvd
CVSS3: 5.9
EPSS Средний

Описание

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
Версия от 4.2 (включая) до 6.1.1 (включая)
cpe:2.3:a:wordpress:wordpress:4.1:-:*:*:*:*:*:*

EPSS

Процентиль: 95%
0.20796
Средний

5.9 Medium

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
debian
больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback ...

CVSS3: 5.9
github
больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

EPSS

Процентиль: 95%
0.20796
Средний

5.9 Medium

CVSS3

Дефекты

CWE-367