Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pq3x-96c3-xgjg

Опубликовано: 23 июл. 2018
Источник: github
Github: Прошло ревью

Описание

Moderate severity vulnerability that affects Products.PlonePAS

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.

Пакеты

Наименование

Products.PlonePAS

pip
Затронутые версииВерсия исправления

>= 3, < 3.9

3.9

EPSS

Процентиль: 64%
0.00464
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 16 лет назад

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.

redhat
больше 16 лет назад

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.

nvd
больше 16 лет назад

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.

debian
больше 16 лет назад

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product ...

EPSS

Процентиль: 64%
0.00464
Низкий

Дефекты

CWE-287