Описание
Plone unauthorized member addition vulnerability
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administrator.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2015-7315
- https://github.com/plone/Products.CMFPlone/commit/1845b0a92312291811b68907bf2aa0fb448c4016
- https://github.com/plone/Products.CMFPlone/commit/9f0111f85cd14f3f067044b59b93e2856c99d542
- https://github.com/zopefoundation/Products.CMFCore/commit/e1d981bfa14b664317285f0f36498f4be4a23406
- https://bugzilla.redhat.com/show_bug.cgi?id=1264791
- https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2017-52.yaml
- https://plone.org/security/hotfix/20150910/anonymous-is-able-to-create-plone-members
- https://pypi.org/project/Products.PloneHotfix20150910
- http://www.openwall.com/lists/oss-security/2015/09/22/13
Пакеты
Products.CMFPlone
>= 3.3.0, < 4.3.6
4.3.7
Products.CMFPlone
>= 5.0a1, < 5.0rc2
5.0rc2
Plone
>= 3.3, <= 3.3.6
Отсутствует
Plone
>= 4.0a1, <= 4.0.10
Отсутствует
Plone
>= 4.1a1, <= 4.1.6
Отсутствует
Plone
>= 4.2a1, <= 4.2.7
Отсутствует
Plone
>= 4.3a1, <= 4.3.6
Отсутствует
Plone
= 5.0rc1
Отсутствует
Связанные уязвимости
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administrator.
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administrator.