Junglewise Threat Intelligence

CVE-2024-34528: PYSEC-2024-175 - WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because the conf_path os.open does not use a mode parameter

CVE-2024-34528 · Severity: low · CVSS 3.1 · Published 2024-05-06

Vendors: PyPI.

Executive brief

WordOps is a web server management tool used to automate WordPress deployment and configuration. A timing vulnerability in how it creates and secures configuration files allows an attacker with local system access to read or modify sensitive configuration data during a narrow window between file creation and permission changes, potentially leading to unauthorized access to database credentials or other sensitive settings.

Technical details

A Time-Of-Check-To-Time-Of-Use (TOCTOU) race condition exists in wo/cli/plugins/stack_pref.py where the os.open() call to create the conf_path file does not specify a restrictive mode parameter. This allows file permissions to remain overly permissive between file creation and the subsequent chmod call, creating an exploitable window. An attacker with local system access can race to read or modify the file before permissions are tightened. The vulnerability affects versions through 3.20.0 and is fixed in 3.21.0.

Affected products

  • WordOps WordOps through 3.20.0

Timeline

  • 2024-05-06: disclosed: Published to GitHub Advisory Database
  • 2024-05-06: patched: Fixed in version 3.21.0

References