Safety vulnerability ID: 41880
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Plone-app-contenttypes version 2.1.6 includes a fix for CVE-2020-7941: A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.
Latest version: 2.2.3
Default content types for Plone based on Dexterity
------------------
Bug fixes:
- Integrate PloneHotFix20200121: add more permission checks.
See https://plone.org/security/hotfix/20200121/privilege-escalation-for-overwriting-content
[maurits] (3021)
- Add a guard in the document.pt template to allow the Document type not to have the RichText
enforce the behavior enabled.
[sneridagh] (3047)
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application