Jetpack < 2.9.3 - Security Bypass

2014-08-26 00:00
Anonymous

Strategic Overview

Status
Patched in 1.9.4
Affected Version1.8 – 2.9.2 · 12 branches
CVSS5.3Medium
CVECVE-2014-0173
View all Jetpack – WP Security, Backup, Speed, & Growth vulnerabilities

Vulnerability Overview

The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly restrict access to the XML-RPC service, which allows remote attackers to bypass intended restrictions and publish posts via unspecified vectors. NOTE: some of these details are obtained from third party information.

Technical Analysis

REMEDIATION: Update to one of the following versions, or a newer patched version: 1.9.4, 2.0.9, 2.1.4, 2.2.7, 2.3.7, 2.4.4, 2.5.2, 2.6.3, 2.7.2, 2.8.2, 2.9.3 --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C