‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. tptacek · · focus · HN ↗
    These CVSS scores don't mean anything and it would be better for everyone if they stopped showing up in headlines. This is a somewhat situational Wordpress RCE that impacts only a couple themes.
    1. paulez · · focus · HN ↗
      This score specifically means that given some specific conditions, anyone can execute code over the network on a vulnerable WordPress setup. Is this not true?
      1. tptacek · · focus · HN ↗
        I'm not saying that the vulnerability isn't severe or important to people running Wordpress, only that CVSS scores are literally a Ouija Board that can come out to whatever the user wants them to.
        1. nicce · · focus · HN ↗
          > CVSS scores are literally a Ouija Board that can come out to whatever the user wants them to.

          Not really. They are very good at describing the technical impact. Sometimes pre-condition is very rare and that reduces overall likelihood but for those few it applies, the impact still could be catastrophic. Who wants to risk it if whole business could go down?

          1. akerl_ · · focus · HN ↗
            So if I get a 9.8 that doesn't apply to my usage, what is the CVSS score doing for me?
            1. cleansy · · focus · HN ↗
              Published CVSS is a base score that gives you a hint of how important the analysis of a vulnerability is to prioritise the patching or mitigation. What you see on websites is only ever the base spiciness so to speak. If you have for example wordpress only running in an isolated environment behind internal firewall rules you‘d downgrade it accordingly. It’s a imperfect metric but so far the best we have to signal priorities. It’s all described in its spec that no one seems to read and websites also communicate it badly.
              1. akerl_ · · focus · HN ↗
                CVSS is impossible to communicate effectively. We don't need a metric; I'm already going to have to read and assess the vulnerability to decide how I actually want to assess the risk given my infrastructure, so the number's not doing me any good.

                This isn't just a CVSS issue: there have been a variety of attempts to reduce a risk score down to a single general number and they all end up as somewhere between marketing material, scare tactic, and junk science.

                1. nicce · · focus · HN ↗
                  > We don't need a metric; I'm already going to have to read and assess the vulnerability to decide how I actually want to assess the risk given my infrastructure, so the number's not doing me any good.

                  Would you say that vulnerability with CVSS score that points to low is equally important to verify and take care of than CVSS which points to critical?

                  1. akerl_ · · focus · HN ↗
                    Yes. I believe that using CVSS scores as a first pass to decide which vulnerabilities to review is risky.

                    The most boring reason, even if you take CVSS scores at face value, is that in many cases it is possible to leverage multiple "low" severity vulnerabilities into a massive impact.

                    But the bigger reason is that CVSS scores are all over the place, and the people operating roulette wheel that generates them do not have any insight into any specific person's systems.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.