CVE-2019-17673Improper Input Validation in Wordpress

Severity
7.5HIGHNVD
EPSS
3.6%
top 12.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17
Latest updateMay 24

Description

WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wordpress< wordpress 5.2.4+dfsg1-1 (bookworm)
NVDwordpress/wordpress< 5.2.4
Debianwordpress/wordpress< 5.2.4+dfsg1-1+3

Also affects: Debian Linux 10.0, 9.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-93gm-xcwj-q3j2: WordPress before 52022-05-24
OSV
CVE-2019-17673: WordPress before 52019-10-17

📋Vendor Advisories

1
Debian
CVE-2019-17673: wordpress - WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET reque...2019

💬Community

8
HackerOne
Version problem in wordpress leads to the many vulnearability2020-01-10
Bugzilla
CVE-2019-17673 wordpress: JSON request cache poisoning [epel-7]2019-11-22
Bugzilla
CVE-2019-17673 wordpress: JSON request cache poisoning [fedora-all]2019-11-22
Bugzilla
CVE-2019-17673 wordpress: JSON request cache poisoning [epel-6]2019-11-22
Bugzilla
CVE-2019-17673 wordpress: JSON request cache poisoning [fedora-all]2019-11-21
CVE-2019-17673 — Improper Input Validation in Wordpress | cvebase