Lucene search

K
osvGoogleOSV:GHSA-GC9G-67CQ-P7V4
HistoryJun 15, 2021 - 4:12 p.m.

Server-Side Request Forgery in Plone

2021-06-1516:12:04
Google
osv.dev
10
plone
ssrf
diazo themes
dexterity ttw schemas
plone.app.theming
plone.app.dexterity
plone.supermodel
lxml.parser security issue

EPSS

0.002

Percentile

55.1%

Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.

EPSS

0.002

Percentile

55.1%

Related for OSV:GHSA-GC9G-67CQ-P7V4