Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Fedora 31: FEDORA-2019-f21ad78845 Moderate: WordPress XSS Attacks

fedora
Calendar Grey October 26, 2019
Dist Fedora Esm H88
WordPress 5.2.4 resolves several urgent security vulnerabilities in Fedora 31. Update now to safeguard against XSS and additional threats.
**WordPress 5.2.4 Security Release** WordPress versions 5.2.3 and earlier are affected by these bugs, which are fixed in version 5.2.4

Summary

Wordpress is an online publishing / weblog package that makes it very easy,

almost trivial, to get information out to people on the web.

Important information in /usr/share/doc/wordpress/README.fedora

**WordPress 5.2.4 Security Release** WordPress versions 5.2.3 and earlier are

affected by these bugs, which are fixed in version 5.2.4. **Security Updates**

* Props to Evan Ricafort for finding an issue where stored XSS (cross-site

scripting) could be added via the Customizer. * Props to J.D. Grimes who

found and disclosed a method of viewing unauthenticated posts. * Props to

Weston Ruter for finding a way to create a stored XSS to inject Javascript into

style tags. * Props to David Newman for highlighting a method to poison the

cache of JSON GET requests via the Vary: Origin header. * Props to Eugene

Kolodenker who found a server-side request forgery in the way that URLs are

validated. * Props to Ben Bidner of the WordPress Security Team who

discovered issues related to referrer validation in the admin.

* Tue Oct 15 2019 Remi Collet - 5.2.4-1

- WordPress 5.2.4 Security Release

su -c 'dnf upgrade --advisory FEDORA-2019-f21ad78845' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 31
Version: 5.2.4
Release: 1.fc31
Summary: Blog tool and publishing platform

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here