‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. tptacek · · focus · HN ↗
    These CVSS scores don't mean anything and it would be better for everyone if they stopped showing up in headlines. This is a somewhat situational Wordpress RCE that impacts only a couple themes.
    1. paulez · · focus · HN ↗
      This score specifically means that given some specific conditions, anyone can execute code over the network on a vulnerable WordPress setup. Is this not true?
      1. tptacek · · focus · HN ↗
        I'm not saying that the vulnerability isn't severe or important to people running Wordpress, only that CVSS scores are literally a Ouija Board that can come out to whatever the user wants them to.
        1. nicce · · focus · HN ↗
          > CVSS scores are literally a Ouija Board that can come out to whatever the user wants them to.

          Not really. They are very good at describing the technical impact. Sometimes pre-condition is very rare and that reduces overall likelihood but for those few it applies, the impact still could be catastrophic. Who wants to risk it if whole business could go down?

          1. akerl_ · · focus · HN ↗
            So if I get a 9.8 that doesn't apply to my usage, what is the CVSS score doing for me?
            1. cleansy · · focus · HN ↗
              Published CVSS is a base score that gives you a hint of how important the analysis of a vulnerability is to prioritise the patching or mitigation. What you see on websites is only ever the base spiciness so to speak. If you have for example wordpress only running in an isolated environment behind internal firewall rules you‘d downgrade it accordingly. It’s a imperfect metric but so far the best we have to signal priorities. It’s all described in its spec that no one seems to read and websites also communicate it badly.
              1. vntok · · focus · HN ↗
                Yes. It's amazing how supposedly security professionals only take the base score "as is" and never adjust.

                Many GUI CVSS calculators exist just for this, it takes a minute to requalify a vuln and adjust its CVSS based on your specific environment.

                This one for example is pretty basic but works well: <a href="https:&#x2F;&#x2F;www.first.org&#x2F;cvss&#x2F;calculator&#x2F;4.0" rel="nofollow">https:&#x2F;&#x2F;www.first.org&#x2F;cvss&#x2F;calculator&#x2F;4.0

                &gt; These metrics enable the analyst to customize the CVSS score depending on the importance of the affected IT asset to a user’s organization, measured in terms of complementary&#x2F;alternative security controls in place, Confidentiality, Integrity, and Availability. The metrics are the modified equivalent of base metrics and are assigned metric values based on the component placement in organization infrastructure.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.