‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. tptacek · · focus · HN ↗
    These CVSS scores don't mean anything and it would be better for everyone if they stopped showing up in headlines. This is a somewhat situational Wordpress RCE that impacts only a couple themes.
    1. paulez · · focus · HN ↗
      This score specifically means that given some specific conditions, anyone can execute code over the network on a vulnerable WordPress setup. Is this not true?
      1. tptacek · · focus · HN ↗
        I'm not saying that the vulnerability isn't severe or important to people running Wordpress, only that CVSS scores are literally a Ouija Board that can come out to whatever the user wants them to.
        1. nicce · · focus · HN ↗
          > CVSS scores are literally a Ouija Board that can come out to whatever the user wants them to.

          Not really. They are very good at describing the technical impact. Sometimes pre-condition is very rare and that reduces overall likelihood but for those few it applies, the impact still could be catastrophic. Who wants to risk it if whole business could go down?

          1. akerl_ · · focus · HN ↗
            So if I get a 9.8 that doesn't apply to my usage, what is the CVSS score doing for me?
            1. vntok · · focus · HN ↗
              You need to reason about both probability and impact, not one or the other. In your example, it just means that the probability is very low, perhaps even down to 0 in your specific case. But even at a low probability, the impact of the vulnerability remains very high so it helps you reason about it.

              For example, you might react differently to these scores:

              - <8/10: check that your systems are indeed secure

              - 8.6/10: check that your systems are indeed secure and tell your junior analyst to train on creating a custom monitoring rule for that attack and follow-up with you

              - 9.8/10: double-check that your systems are indeed secure, ensure that if you had a hole another security layer would have caught it (if not, that's a problem!), set up a honeypot to get some info on the assholes that have repeatedly attacked you lately and will undoubtedly try to 0-day you in the next few hours, etc.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.