Bug 1831580 (CVE-2020-11030)

Summary: CVE-2020-11030 wordpress: special crafted payload can lead to scripts getting executed within the search block of the block editor
Product: [Other] Security Response Reporter: Michael Kaplan <mkaplan>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: fedora, kevin
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: wordpress 5.4.1 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-28 05:26:11 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1831581, 1831582    
Bug Blocks:    

Description Michael Kaplan 2020-05-05 10:43:05 UTC
An issue have been found in WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

Upstream Advisory:

https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-vccm-6gmc-qhjh

Comment 1 Michael Kaplan 2020-05-05 10:43:33 UTC
Created wordpress tracking bugs for this issue:

Affects: epel-6 [bug 1831581]
Affects: epel-7 [bug 1831582]