CVE-2022-3590
14.12.2022, 09:15
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
Vendor | Product | Version |
---|---|---|
wordpress | wordpress | 4.2 ≤ 𝑥 ≤ 6.1.1 |
wordpress | wordpress | 4.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases