Lucene search

K
nvd[email protected]NVD:CVE-2011-4030
HistoryOct 10, 2011 - 10:55 a.m.

CVE-2011-4030

2011-10-1010:55:06
CWE-264
web.nvd.nist.gov
5

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0.967

Percentile

99.7%

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.

Affected configurations

Nvd
Node
plonecmfeditionsMatch2.0a1
OR
plonecmfeditionsMatch2.0b1
OR
plonecmfeditionsMatch2.0b2
OR
plonecmfeditionsMatch2.0b3
OR
plonecmfeditionsMatch2.0b4
OR
plonecmfeditionsMatch2.0b5
OR
plonecmfeditionsMatch2.0b6
OR
plonecmfeditionsMatch2.0b7
OR
plonecmfeditionsMatch2.0b8
OR
plonecmfeditionsMatch2.0b9
OR
ploneploneMatch4.0
OR
ploneploneMatch4.0.1
OR
ploneploneMatch4.0.2
OR
ploneploneMatch4.0.3
OR
ploneploneMatch4.0.4
OR
ploneploneMatch4.0.5
OR
ploneploneMatch4.0.6.1
OR
ploneploneMatch4.0.7
OR
ploneploneMatch4.0.8
OR
ploneploneMatch4.0.9
OR
ploneploneMatch4.1
OR
ploneploneMatch4.2
OR
ploneploneMatch4.2a1
OR
ploneploneMatch4.2a2
VendorProductVersionCPE
plonecmfeditions2.0a1cpe:2.3:a:plone:cmfeditions:2.0a1:*:*:*:*:*:*:*
plonecmfeditions2.0b1cpe:2.3:a:plone:cmfeditions:2.0b1:*:*:*:*:*:*:*
plonecmfeditions2.0b2cpe:2.3:a:plone:cmfeditions:2.0b2:*:*:*:*:*:*:*
plonecmfeditions2.0b3cpe:2.3:a:plone:cmfeditions:2.0b3:*:*:*:*:*:*:*
plonecmfeditions2.0b4cpe:2.3:a:plone:cmfeditions:2.0b4:*:*:*:*:*:*:*
plonecmfeditions2.0b5cpe:2.3:a:plone:cmfeditions:2.0b5:*:*:*:*:*:*:*
plonecmfeditions2.0b6cpe:2.3:a:plone:cmfeditions:2.0b6:*:*:*:*:*:*:*
plonecmfeditions2.0b7cpe:2.3:a:plone:cmfeditions:2.0b7:*:*:*:*:*:*:*
plonecmfeditions2.0b8cpe:2.3:a:plone:cmfeditions:2.0b8:*:*:*:*:*:*:*
plonecmfeditions2.0b9cpe:2.3:a:plone:cmfeditions:2.0b9:*:*:*:*:*:*:*
Rows per page:
1-10 of 241

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0.967

Percentile

99.7%