Safety vulnerability ID: 35441
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Plone 4.1, 4.2.5 and 4.3.1 include a fix for CVE-2013-4189: Multiple unspecified vulnerabilities in (1) dataitems.py, (2) get.py, and (3) traverseName.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users with administrator access to a subtree to access nodes above the subtree via unknown vectors.
Latest version: 6.1.1
The Plone Content Management System
Multiple unspecified vulnerabilities in (1) dataitems.py, (2) get.py, and (3) traverseName.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users with administrator access to a subtree to access nodes above the subtree via unknown vectors.
MLIST:[oss-security] 20130801 Re: CVE Request -- Plone: 20130618 Hotfix (multiple vectors): http://seclists.org/oss-sec/2013/q3/261
CONFIRM:http://plone.org/products/plone-hotfix/releases/20130618: http://plone.org/products/plone-hotfix/releases/20130618
CONFIRM:http://plone.org/products/plone/security/advisories/20130618-announcement: http://plone.org/products/plone/security/advisories/20130618-announcement
CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=978450: https://bugzilla.redhat.com/show_bug.cgi?id=978450
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application