Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9m4g-f42q-vrrh

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.5
CVSS3: 9.9

Описание

Plone Sandbox Bypass

The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.

Пакеты

Наименование

Plone

pip
Затронутые версииВерсия исправления

< 4.2.3

4.2.3

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 4.3a0, < 4.3b1

4.3b1

EPSS

Процентиль: 75%
0.01711
Низкий

6.5 Medium

CVSS4

9.9 Critical

CVSS3

Дефекты

CWE-693

Связанные уязвимости

redhat
почти 14 лет назад

The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.

nvd
почти 12 лет назад

The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.

debian
почти 12 лет назад

The sandbox whitelisting function (allowmodule.py) in Plone before 4.2 ...

EPSS

Процентиль: 75%
0.01711
Низкий

6.5 Medium

CVSS4

9.9 Critical

CVSS3

Дефекты

CWE-693