CVE-2009-2335
EPSS 85.0%
描述
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."
如何修補 CVE-2009-2335
要修補 CVE-2009-2335,請將受影響套件升級到下列已修補版本。
- Debian/wordpress—升級至 2.8.3-1 或更新版本
CVE-2009-2335 正在被利用嗎?
可能 — EPSS 為 85.0%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 2.8.3-1