CVE-2024-31229: WordPress Really Simple SSL plugin <= 7.2.3 - Server Side Request Forgery (SSRF) vulnerability
Published Apr 18, 2024
·Updated
Server-Side Request Forgery (SSRF) vulnerability in Really Simple Plugins Really Simple SSL.This issue affects Really Simple SSL: from n/a through 7.2.3.
Affected Software
1 affected component
wordpress/really-simple-ssl<=7.2.3
Remediation
Information
Update to 8.0.0 or a higher version.
Event History
Apr 18, 2024
CVE Published
via MITRE·10:28 AM
Data Sourced
via MITRE·10:28 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31229?
CVE-2024-31229 is classified as a medium severity Server-Side Request Forgery (SSRF) vulnerability affecting Really Simple SSL.
2
How do I fix CVE-2024-31229?
To fix CVE-2024-31229, upgrade Really Simple SSL to version 7.2.4 or higher, where the vulnerability has been patched.
3
What software is affected by CVE-2024-31229?
CVE-2024-31229 affects Really Simple SSL versions up to and including 7.2.3.
4
What are the potential impacts of CVE-2024-31229?
The potential impacts of CVE-2024-31229 include unauthorized access to internal services and exposure of sensitive data.
5
Who is the vendor for CVE-2024-31229?
The vendor for CVE-2024-31229 is Really Simple Plugins, the developers of Really Simple SSL.