CVE-2022-3590
14.12.2022, 09:15
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
| Vendor | Product | Version |
|---|---|---|
| wordpress | wordpress | 4.2 ≤ 𝑥 ≤ 6.1.1 |
| wordpress | wordpress | 4.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases