Safety vulnerability ID: 25996
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Plone 4.3 includes a fix for CVE-2012-5486: It was discovered that Plone, included as a part of luci, did not properly sanitize HTTP headers provided within certain URL requests. A remote attacker could use a specially crafted URL that, when processed, would cause the injected HTTP headers to be returned as a part of the Plone HTTP response, potentially allowing the attacker to perform other more advanced attacks.
Latest version: 6.1.1
The Plone Content Management System
ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application