CVE-2019-17669: SSRF
Published Oct 17, 2019
·Updated
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
Affected Software
5 affected componentsFixes available
debian/wordpress
5.0.15+dfsg1-0+deb10u15.0.19+dfsg1-0+deb10u15.7.8+dfsg1-0+deb11u26.1.1+dfsg1-16.3.1+dfsg1-1
WordPress WordPress<5.2.4
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Remediation
Event History
Oct 17, 2019
CVE Published
via MITRE·12:03 PM
Data Sourced
via MITRE·12:03 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17669?
CVE-2019-17669 is classified as a moderate severity vulnerability due to its potential exploitation through Server Side Request Forgery (SSRF).
2
How do I fix CVE-2019-17669?
To fix CVE-2019-17669, update your WordPress installation to version 5.2.4 or later.
3
Which versions of WordPress are affected by CVE-2019-17669?
WordPress versions prior to 5.2.4 are affected by CVE-2019-17669.
4
What is the nature of the vulnerability in CVE-2019-17669?
CVE-2019-17669 is a Server Side Request Forgery (SSRF) vulnerability due to improper URL validation.
5
Can CVE-2019-17669 impact my site's security?
Yes, CVE-2019-17669 can potentially allow attackers to make unauthorized requests from your server, compromising your site's security.