WordPress.org

Make WordPress Core

Opened 13 months ago

Closed 13 months ago

Last modified 12 months ago

#45046 closed defect (bug) (invalid)

IP validation improper loophole repair

Reported by: wooir Owned by:
Milestone: Priority: normal
Severity: normal Version: 4.9.8
Component: HTTP API Keywords:
Focuses: Cc:
PR Number:

Description (last modified by SergeyBiryukov)

wp-includes/http.php
563 lines:

if ( 127 === $parts[0] || 10 === $parts[0] || 0 === $parts[0]

It should be modified to:

if ( 127 === $parts[0] || 10 === $parts[0] || 0 === $parts[0] || 0 === $parts[0]

Change History (4)

#1 follow-up: @johnbillion
13 months ago

  • Keywords reporter-feedback added

Can you provide some more information about what problem this change addresses please?

#2 in reply to: ↑ 1 @wooir
13 months ago

  • Resolution set to invalid
  • Status changed from new to closed

Replying to johnbillion:

Can you provide some more information about what problem this change addresses please?

Sorry, I tested it and found that I was mistaken.

#3 @netweb
13 months ago

  • Milestone Awaiting Review deleted

#4 @SergeyBiryukov
12 months ago

  • Component changed from General to HTTP API
  • Description modified (diff)
  • Keywords reporter-feedback removed
Note: See TracTickets for help on using tickets.