Compare commits

..
11 Commits
Author SHA1 Message Date
moritz fe2f0087cd remove ftp container from selfmanaged 2026-08-12 01:56:53 +02:00
moritz d3cae49f8d remove image from selfmanaged 2026-08-12 01:12:03 +02:00
simon 7126fb291d chore: publish 2.19.4+6.9.4 release
continuous-integration/drone/tag Build is passing
2026-07-21 13:53:49 +02:00
simon 71ffa2a1db block wp2shell CVE-2026-63030 2026-07-21 13:52:43 +02:00
simon d271532f31 chore: publish 2.19.3+6.9.4 release
continuous-integration/drone/tag Build is passing
2026-07-21 10:32:50 +02:00
simon 2390db2f0d Merge commit '3fc6a704' into kc-stable 2026-07-21 10:29:12 +02:00
simon 3fc6a7048d block XML-RPC 2026-07-21 10:26:44 +02:00
simon 15be511b4c block XML-RPC 2026-07-20 16:39:44 +02:00
moritz 332ab0b97d chore: publish 2.19.2+6.9.4 release
continuous-integration/drone/tag Build is passing
continuous-integration/drone/push Build is failing
2026-04-28 02:25:26 +02:00
moritz 3b598e82dd harden htaccess 2026-04-28 01:57:52 +02:00
moritz 8e81f3f81c selfmanaged wordpress 2026-04-28 01:54:50 +02:00
7 changed files with 39 additions and 19 deletions
+7 -7
View File
@@ -1,8 +1,8 @@
export PHP_UPLOADS_CONF_VERSION=v4 export PHP_UPLOADS_CONF_VERSION=v4
export ENTRYPOINT_CONF_VERSION=v7 export ENTRYPOINT_CONF_VERSION=v8
export ENTRYPOINT_MAILRELAY_CONF_VERSION=v2 export ENTRYPOINT_MAILRELAY_CONF_VERSION=v2
export MSMTP_CONF_VERSION=v4 export MSMTP_CONF_VERSION=v4
export HTACCESS_CONF_VERSION=v3 export HTACCESS_CONF_VERSION=v4
export USERS_CONF_VERSION=v1 export USERS_CONF_VERSION=v1
wp() { wp() {
@@ -42,11 +42,11 @@ core_install(){
} }
enable_auto_updates(){ enable_auto_updates(){
wp plugin deactivate disable-update-notifications --allow-root wp "plugin deactivate disable-update-notifications --allow-root"
wp plugin uninstall disable-update-notifications --allow-root wp "plugin uninstall disable-update-notifications --allow-root"
wp option delete disable_notification_setting --allow-root wp "option delete disable_notification_setting --allow-root"
wp plugin auto-updates enable --all --allow-root wp "plugin auto-updates enable --all --allow-root"
wp theme auto-updates enable --all --allow-root wp "theme auto-updates enable --all --allow-root"
} }
disable_auto_updates(){ disable_auto_updates(){
+3 -4
View File
@@ -3,7 +3,6 @@ version: "3.8"
services: services:
app: app:
image: "wordpress:latest"
volumes: volumes:
- "wordpress:/var/www/html/" - "wordpress:/var/www/html/"
environment: environment:
@@ -13,9 +12,9 @@ services:
define( 'FS_METHOD', 'direct' ); define( 'FS_METHOD', 'direct' );
${WORDPRESS_CONFIG_EXTRA} ${WORDPRESS_CONFIG_EXTRA}
ftp: #ftp:
volumes: # volumes:
- "wordpress:/home/ftp_user/" # - "wordpress:/home/ftp_user/"
volumes: volumes:
wordpress: wordpress:
+1 -1
View File
@@ -62,7 +62,7 @@ services:
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectregex.replacement=https://${DOMAIN}/$${2}" - "traefik.http.middlewares.${STACK_NAME}-redirect.redirectregex.replacement=https://${DOMAIN}/$${2}"
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectregex.permanent=true" - "traefik.http.middlewares.${STACK_NAME}-redirect.redirectregex.permanent=true"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
- "coop-cloud.${STACK_NAME}.version=2.19.1+6.9.4" - "coop-cloud.${STACK_NAME}.version=2.19.4+6.9.4"
db: db:
image: "mariadb:12.2" image: "mariadb:12.2"
+13
View File
@@ -42,6 +42,19 @@ define('FORCE_SSL_ADMIN', true );
define('COOKIE_DOMAIN', \$_SERVER['HTTP_HOST']);" define('COOKIE_DOMAIN', \$_SERVER['HTTP_HOST']);"
{{ end }} {{ end }}
UPLOADS_HTACCESS=/var/www/html/wp-content/uploads/.htaccess
if [ ! -f "$UPLOADS_HTACCESS" ]; then
mkdir -p /var/www/html/wp-content/uploads
cat > "$UPLOADS_HTACCESS" <<'EOF'
# Prevent PHP execution in uploads directory
<FilesMatch "\.(?i:php|phtml|phar)$">
Require all denied
</FilesMatch>
EOF
chown www-data:www-data "$UPLOADS_HTACCESS"
fi
if [ -n "$@" ]; then if [ -n "$@" ]; then
"$@" "$@"
fi fi
+13 -7
View File
@@ -3,12 +3,18 @@
Require all denied Require all denied
</FilesMatch> </FilesMatch>
# Prevent PHP execution in uploads directory # Block XML-RPC
<Directory /var/www/html/wp-content/uploads> <Files xmlrpc.php>
<FilesMatch "\.(?i:php|phtml|phar)$"> Require all denied
Require all denied </Files>
</FilesMatch>
</Directory> # Block wp2shell CVE-2026-63030
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteCond %{QUERY_STRING} rest_route=.*/batch/v1 [NC]
RewriteRule .* - [F,L]
RewriteRule ^wp-json/batch/v1 - [F,L]
</IfModule>
{{ if eq (env "MULTISITE") "" -}} {{ if eq (env "MULTISITE") "" -}}
# BEGIN WordPress # BEGIN WordPress
@@ -66,4 +72,4 @@ RewriteRule ^(.*\.php)$ $1 [L]
RewriteRule . index.php [L] RewriteRule . index.php [L]
# END WordPress Multisite # END WordPress Multisite
{{- end }} {{- end }}
+1
View File
@@ -0,0 +1 @@
patch to block XML-RPC via htaccess
+1
View File
@@ -0,0 +1 @@
temporarily block rest api against wp2shell CVE