WordPress: Unauthenticated path traversal leading to conditional RCE
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
WordPress: Unauthenticated path traversal leading to conditional RCE
Unofficial Hacker News client; not affiliated with Y Combinator.
tptacek · · focus · HN ↗
paulez · · focus · HN ↗
tptacek · · focus · HN ↗
nicce · · focus · HN ↗
Not really. They are very good at describing the technical impact. Sometimes pre-condition is very rare and that reduces overall likelihood but for those few it applies, the impact still could be catastrophic. Who wants to risk it if whole business could go down?
akerl_ · · focus · HN ↗
cleansy · · focus · HN ↗
akerl_ · · focus · HN ↗
This isn't just a CVSS issue: there have been a variety of attempts to reduce a risk score down to a single general number and they all end up as somewhere between marketing material, scare tactic, and junk science.
nicce · · focus · HN ↗
Would you say that vulnerability with CVSS score that points to low is equally important to verify and take care of than CVSS which points to critical?
akerl_ · · focus · HN ↗
The most boring reason, even if you take CVSS scores at face value, is that in many cases it is possible to leverage multiple "low" severity vulnerabilities into a massive impact.
But the bigger reason is that CVSS scores are all over the place, and the people operating roulette wheel that generates them do not have any insight into any specific person's systems.