Candidate: CVE-2017-17092 PublicDate: 2017-12-02 06:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17092 https://github.com/WordPress/WordPress/commit/67d03a98c2cae5f41843c897f206adde299b0509 https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/ https://codex.wordpress.org/Version_4.9.1 Description: wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=883314 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N [5.4 MEDIUM] Patches_wordpress: upstream_wordpress: released (4.9.1+dfsg-1) precise/esm_wordpress: DNE trusty_wordpress: ignored (reached end-of-life) trusty/esm_wordpress: DNE (trusty was needed) xenial_wordpress: ignored (end of standard support, was needed) zesty_wordpress: ignored (reached end-of-life) artful_wordpress: ignored (reached end-of-life) bionic_wordpress: not-affected (4.9.5+dfsg1-1) cosmic_wordpress: not-affected (4.9.5+dfsg1-1) disco_wordpress: not-affected (4.9.5+dfsg1-1) eoan_wordpress: not-affected (4.9.5+dfsg1-1) focal_wordpress: not-affected (4.9.5+dfsg1-1) groovy_wordpress: not-affected (4.9.5+dfsg1-1) hirsute_wordpress: not-affected (4.9.5+dfsg1-1) impish_wordpress: not-affected (4.9.5+dfsg1-1) jammy_wordpress: not-affected (4.9.5+dfsg1-1) devel_wordpress: not-affected (4.9.5+dfsg1-1)