Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-3590

Опубликовано: 14 дек. 2022
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS3: 5.9

Описание

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/xenial

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

kinetic

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 95%
0.20796
Средний

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVSS3: 5.9
debian
больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback ...

CVSS3: 5.9
github
больше 2 лет назад

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

EPSS

Процентиль: 95%
0.20796
Средний

5.9 Medium

CVSS3