Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 4.9
Описание
Plone Privilege escalation through exposed underlying API
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2013-7061
- https://github.com/plone/Products.CMFPlone/commit/a6a3e50f759da7e7ca46e50777a35e51f4d8ed48
- https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2014-66.yaml
- https://github.com/pypa/advisory-database/tree/main/vulns/products-cmfplone/PYSEC-2014-68.yaml
- https://plone.org/security/20131210/catalogue-exposure
- https://pypi.org/project/Products.PloneHotfix20131210
- http://www.openwall.com/lists/oss-security/2013/12/10/15
- http://www.openwall.com/lists/oss-security/2013/12/12/3
Пакеты
Наименование
Plone
pip
Затронутые версииВерсия исправления
>= 3.3b1, < 4.3.3
4.3.3
Наименование
Products.CMFPlone
pip
Затронутые версииВерсия исправления
>= 3.3, < 4.3.3
4.3.3
Связанные уязвимости
redhat
около 12 лет назад
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.
nvd
почти 12 лет назад
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.