Lucene search

K
githubGitHub Advisory DatabaseGHSA-PWGM-JVQV-6V8P
HistoryMay 17, 2022 - 5:37 a.m.

Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable

2022-05-1705:37:14
GitHub Advisory Database
github.com
4
plone
cmfeditions
anonymous access

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

Low

EPSS

0.967

Percentile

99.7%

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.

Affected configurations

Vulners
Node
ploneploneRange4.2a1–4.2a2
OR
ploneploneRange4.1–4.1.1
OR
ploneploneRange4.0–4.0.9
VendorProductVersionCPE
ploneplone*cpe:2.3:a:plone:plone:*:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

Low

EPSS

0.967

Percentile

99.7%