Safety vulnerability ID: 40534
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.
Latest version: 6.1.1
The Plone Content Management System
Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script. See CVE-2021-33509.
MISC:https://plone.org/security/hotfix/20210518/writing-arbitrary-files-via-docutils-and-python-script: https://plone.org/security/hotfix/20210518/writing-arbitrary-files-via-docutils-and-python-script
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application