[wp-trac] [WordPress Trac] #57363: WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding

WordPress Trac noreply at wordpress.org
Wed Jan 11 14:20:12 UTC 2023


#57363: WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding
------------------------------+------------------------------
 Reporter:  edavis711         |       Owner:  (none)
     Type:  defect (bug)      |      Status:  new
 Priority:  normal            |   Milestone:  Awaiting Review
Component:  Pings/Trackbacks  |     Version:  6.1.1
 Severity:  normal            |  Resolution:
 Keywords:  needs-patch       |     Focuses:
------------------------------+------------------------------

Comment (by paulkevan):

 > A provisional patch does exist, but a number of complicated edge cases
 remain to be resolved, so it’ll take a bit of work to get it into a commit
 worthy state state that doesn’t break existing plugins.

 The work to update the Requests library
 (https://core.trac.wordpress.org/changeset/54997) further complicates this
 and will requires some updates to the original patch.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/57363#comment:6>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list