Oval Definition:oval:com.ubuntu.bionic:def:2019200430000000
Revision Date:2019-12-27Version:1
Title:CVE-2019-20043 on Ubuntu 18.04 LTS (bionic) - medium.
Description:In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-20043
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND wordpress package in bionic is affected and may need fixing.
  • BACK