Safety vulnerability ID: 39377
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role). See CVE-2020-28735.
Latest version: 6.1.1
The Plone Content Management System
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role). See CVE-2020-28735.
CONFIRM:https://dist.plone.org/release/5.2.3/RELEASE-NOTES.txt: https://dist.plone.org/release/5.2.3/RELEASE-NOTES.txt
MISC:https://github.com/plone/Products.CMFPlone/issues/3209: https://github.com/plone/Products.CMFPlone/issues/3209
MISC:https://www.misakikata.com/codes/plone/python-en.html: https://www.misakikata.com/codes/plone/python-en.html
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application