CVE-2017-5493
Summary
| CVE | CVE-2017-5493 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-01-15 02:59:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup. |
Risk And Classification
Problem Types: CWE-338
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Re: CVE Request: Wordpress: 8 security issues in 4.7 | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| Version 4.7.1 « WordPress Codex | CONFIRM | codex.wordpress.org | Release Notes, Vendor Advisory |
| WordPress Cryptographic Security Bypass Vulnerability | BID | www.securityfocus.com | |
| Multisite: Use `wp_rand()` in signup key creation. · WordPress/WordPress@cea9e2d · GitHub | CONFIRM | github.com | Patch |
| WordPress Bugs Let Remote Users Conduct Cross-Site Scripting and Cross-Site Request Forgery Attacks and Obtain Potentially Sensitive Information - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Debian -- Security Information -- DSA-3779-1 wordpress | DEBIAN | www.debian.org | |
| WordPress 4.7.1 Security and Maintenance Release | CONFIRM | wordpress.org | Vendor Advisory |
| WordPress 3.0-4.7 - Cryptographically Weak Pseudo-Random Number Generator (PRNG) | MISC | wpvulndb.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.