Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pwgm-jvqv-6v8p

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.

Пакеты

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 4.0, <= 4.0.9

4.0.10

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 4.1, < 4.1.1

4.1.1

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 4.2a1, <= 4.2a2

4.2a3

EPSS

Процентиль: 78%
0.01098
Низкий

Связанные уязвимости

redhat
больше 14 лет назад

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.

nvd
больше 14 лет назад

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.

debian
больше 14 лет назад

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4 ...

EPSS

Процентиль: 78%
0.01098
Низкий