CVE-2017-9066: SSRF
Published May 18, 2017
·Updated
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
Affected Software
4 affected componentsFixes available
debian/wordpress
5.0.15+dfsg1-0+deb10u15.0.19+dfsg1-0+deb10u15.7.8+dfsg1-0+deb11u26.1.1+dfsg1-16.3.1+dfsg1-1
WordPress WordPress<=4.7.4
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Patch Available
Event History
May 18, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9066?
CVE-2017-9066 is classified as a moderate severity vulnerability due to its potential for Server-Side Request Forgery (SSRF).
2
How do I fix CVE-2017-9066?
To fix CVE-2017-9066, upgrade your WordPress installation to version 4.7.5 or later.
3
What versions of WordPress are affected by CVE-2017-9066?
CVE-2017-9066 affects all WordPress versions prior to 4.7.5.
4
What type of vulnerability is CVE-2017-9066?
CVE-2017-9066 is a Server-Side Request Forgery (SSRF) vulnerability caused by insufficient redirect validation.
5
Which environments are impacted by CVE-2017-9066?
CVE-2017-9066 impacts WordPress installations on Debian Linux versions 8.0 and 9.0.