Safety vulnerability ID: 35982
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Products-plonepas 3.9 fixes the cookie plugin's login handler to not trust the username from the request. Instead, now it's used the login name of the currently authenticated user. This fixes CVE-2009-0662.
Latest version: 6.0.8
PlonePAS modifies the PluggableAuthService for use by Plone.
----------------
- Fix the cookie plugin's login handler to not trust the username
from the request. Instead we use the login name of the currently
authenticated user. This fixes CVE-2009-0662 (see
http://plone.org/products/plone/security/advisories/cve-2009-0662
for more information).
[wichert]
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application