Candidate: CVE-2017-17091 PublicDate: 2017-12-02 06:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17091 https://github.com/WordPress/WordPress/commit/eaf1cfdc1fe0bdffabd8d879c591b864d833326c https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/ https://codex.wordpress.org/Version_4.9.1 Description: wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=883314 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_wordpress: upstream_wordpress: released (4.9.1+dfsg-1) precise/esm_wordpress: DNE trusty_wordpress: ignored (reached end-of-life) trusty/esm_wordpress: DNE (trusty was needed) xenial_wordpress: ignored (end of standard support, was needed) zesty_wordpress: ignored (reached end-of-life) artful_wordpress: ignored (reached end-of-life) bionic_wordpress: not-affected (4.9.5+dfsg1-1) cosmic_wordpress: not-affected (4.9.5+dfsg1-1) disco_wordpress: not-affected (4.9.5+dfsg1-1) eoan_wordpress: not-affected (4.9.5+dfsg1-1) focal_wordpress: not-affected (4.9.5+dfsg1-1) groovy_wordpress: not-affected (4.9.5+dfsg1-1) hirsute_wordpress: not-affected (4.9.5+dfsg1-1) impish_wordpress: not-affected (4.9.5+dfsg1-1) jammy_wordpress: not-affected (4.9.5+dfsg1-1) devel_wordpress: not-affected (4.9.5+dfsg1-1)