Lucene search

K
osvGoogleOSV:GHSA-HM2P-FHWX-9285
HistoryJun 15, 2021 - 4:11 p.m.

Incorrect Permission Assignment for Critical Resource in Plone

2021-06-1516:11:38
Google
osv.dev
16
plone
remote authenticated managers
disk i/o
restructuredtext
python script

EPSS

0.003

Percentile

70.9%

Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.

EPSS

0.003

Percentile

70.9%

Related for OSV:GHSA-HM2P-FHWX-9285