Safety vulnerability ID: 41877
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Plone-app-layout version 3.4.1 integrates a fix for CVE-2020-7937, which affects the core package Plone.
https://plone.org/security/hotfix/20200121/xss-in-the-title-field-on-plone-5-0-and-higher
Latest version: 3.5.1
Layout mechanisms for Plone
------------------
Bug fixes:
- Analytics viewlet: make webstats_js a property, so that it does not rely on an a call to the update method to be correctly evaluated [ale-rt] (227)
- Code formating according to Plone standards (black, isort).
[thet] (230)
- Remove selectedTabs and update method from GlobalSectionsViewlet as both are now unused.
[thet] (231)
- Remove deprecation warnings [ale-rt] (233)
- Integrate Plone20200121 hotfix: prevent XSS in title.
Part of https://plone.org/security/hotfix/20200121/xss-in-the-title-field-on-plone-5-0-and-higher
[maurits] (3021)
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application