Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qc57-h2f7-p4hx

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Plone Unauthorized Access Vulnerability

Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.

Пакеты

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 2.5, < 4.3.16

4.3.16

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 5.0, < 5.1.0

5.1.0

EPSS

Процентиль: 52%
0.00294
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 3.1
redhat
около 8 лет назад

Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.

CVSS3: 6.5
nvd
около 8 лет назад

Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.

EPSS

Процентиль: 52%
0.00294
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-284