oss-sec mailing list archives
Re: Asking for a CVE id for the WordPress Privilege Escalation vulnerability (4.7/4.7.1)
From: Josh Bressers <josh () bress net>
Date: Fri, 10 Feb 2017 16:14:41 -0600
On Fri, Feb 10, 2017 at 2:18 PM, Marc-Alexandre Montpas <marc () sucuri net> wrote:
Hi there, Per Josh's request, I'm sending the details here. There was a Privilege Escalation vulnerability in WordPress version 4.7 and 4.7.1, which allowed attackers to edit any posts on a vulnerable site. The issue was caused by an inconsistent use of numeric IDs which made it possible for an attacker to make use of PHP's type juggling features to bypass the privilege check mechanisms put in place. More information here: https://blog.sucuri.net/2017/02/content-injection- vulnerability-wordpress-rest-api.html
I know this is sort of out of the blue, but it strikes me as very important, so I'm going to deal with this request right now. I'm helping Kurt with some DWF tasks and this CVE request showed up. I can't find a reference to a previous request for this issue, it's also very high profile and I'm told being exploited in the wild. I'm not seeing a previous request for the latest wordpress issue. I don't want an assignment request to wait until after the weekend. It's #4 on the wordpress site: https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/ I saw 1-3 had CVE IDs requested on January 27th. Let's use CVE-2017-1001000 for #4 Thanks. -- JB
Current thread:
- Re: Asking for a CVE id for the WordPress Privilege Escalation vulnerability (4.7/4.7.1) Josh Bressers (Feb 10)