Oval Definition:oval:com.ubuntu.disco:def:2017149900000000
Revision Date:2017-10-03Version:1
Title:CVE-2017-14990 on Ubuntu 19.04 (disco) - low.
Description:WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-14990
Platform(s):Ubuntu 19.04
Product(s):
Definition Synopsis
  • Ubuntu 19.04 (disco) is installed.
  • AND wordpress package in disco, is related to the CVE in some way and has been fixed (note: '4.8.2+dfsg-2').
  • BACK