Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable
High severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Nov 22, 2024
Package
Affected versions
>= 4.0, <= 4.0.9
>= 4.1, < 4.1.1
>= 4.2a1, <= 4.2a2
Patched versions
4.0.10
4.1.1
4.2a3
Description
Published by the National Vulnerability Database
Oct 10, 2011
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
May 14, 2024
Last updated
Nov 22, 2024
The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.
References