Safety vulnerability ID: 67966
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Plone CMS 3.x uses invariant data (a client username and a server secret) when calculating an HMAC-SHA1 value for an authentication cookie, which makes it easier for remote attackers to gain permanent access to an account by sniffing the network.
Latest version: 6.1.1
The Plone Content Management System
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application