Boletines de Vulnerabilidades

Episode 116: Packagist Patch Shows How Supply Chain Threats Could Impact WordPress


Información sobre el sistema

   
Software afectado Wordpress

Descripción

A vulnerability discovered in Packagist, which is used by Composer to manage PHP package requests, could have allowed attackers to trick Composer into downloading backdoored source code, potentially affecting all WordPress sites. Packagist reports that it’s not aware of any exploits. A SQL injection vulnerability was patched in the CleanTalk AntiSpam plugin installed on over […]

More info:

https://www.wordfence.com/blog/2021/05/episode-116-packagist-patch-shows-how-supply-chain-threats-could-impact-wordpress/

Identificadores estándar

Propiedad Valor
CVE

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2021-05-11

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT