|
Message-ID: <20160108140715.GA25718@eldamar.local> Date: Fri, 8 Jan 2016 15:07:15 +0100 From: Salvatore Bonaccorso <carnil@...ian.org> To: OSS Security Mailinglist <oss-security@...ts.openwall.com> Subject: CVE Request: WordPress: cross-site scripting vulnerability fixed in new 4.4.1 release Hi On 6th of January 2016, a new release of WordPress was posted, https://wordpress.org/news/2016/01/wordpress-4-4-1-security-and-maintenance-release/ > WordPress versions 4.4 and earlier are affected by a cross-site > scripting vulnerability that could allow a site to be compromised. > This was reported by Crtc4L. There is no reference to the fix, but the change seems to be https://core.trac.wordpress.org/changeset/36185 Cf. as well https://twitter.com/brutelogic/status/685105483397619713 Can a CVE be assigned for this WordPress issue? Regards, Salvatore
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.