CVE-2021-24227
Summary
| CVE | CVE-2021-24227 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-12 14:15:00 UTC |
| Updated | 2021-04-14 15:47:00 UTC |
| Description | The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector, an attacker could leak important internal files like wp-config.php, which contains database credentials and cryptographic keys used in the generation of nonces and cookies. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Patreon | Patreon Wordpress | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerabilities Found in Patreon WordPress plugin | MISC | jetpack.com | |
| Attention Required! | Cloudflare | CONFIRM | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: George Stephanis, Fioravante Souza, Miguel Neto, Benedict Singer and Marc Montpas
There are currently no legacy QID mappings associated with this CVE.