Safety vulnerability ID: 41937
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Plone.app.theming 5.0.0a1 and 4.1.6 include a fix for CVE-2021-33511: Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.
https://plone.org/security/hotfix/20210518/server-side-request-forgery-via-lxml-parser
Latest version: 4.1.7
Integrates the Diazo theming engine with Plone
--------------------
Breaking changes:
- Add bootstrap icon from resolver from Plone 6.
[petschki, agitator] (194)
Bug fixes:
- Avoid Server Side Request Forgery via lxml parser.
Taken over from `PloneHotfix20210518 <https://plone.org/security/hotfix/20210518/server-side-request-forgery-via-lxml-parser>`_.
[maurits] (3274)
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application