xmlrpc.php on mariadb.org can lead to DDOS and brute force attacks
Low
M
MariaDB
Submitted None
Team Summary
Official summary from MariaDB
XMLRPC was enabled and accessible on our website. Since we don't need any of the functionality provided by the Wordpress XMLRPC protocol, we were already trying to block XMLRPC requests to our site via our web server configuration, however, due to a syntactic error our enforcing rule did not apply.
Actions:
Reported by
indoappsec
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Uncontrolled Resource Consumption