CVE Vulnerabilities

CVE-2019-17669

Server-Side Request Forgery (SSRF)

Published: Oct 17, 2019 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.

Weakness

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Affected Software

NameVendorStart VersionEnd Version
WordpressWordpress*5.2.4 (excluding)
WordpressUbuntubionic*
WordpressUbuntudisco*
WordpressUbuntueoan*
WordpressUbuntutrusty*
WordpressUbuntuupstream*
WordpressUbuntuxenial*

References