Important note: This is version 2.0 of the hotfix and fixes a critical
issue with version 1.0 of the hotfix. You should update your sites to version
2.0 even if you have already applied version 1.0 of the hotfix. The Plone
security team apologizes for this error.
This hotfix fixes the following four vulnerabilities:
- Reflected XSS attack: A crafted URL can display arbitrary HTML output.
This is a vulnerability in CMFPlone affecting all versions of Plone.
Thanks to S. Streichsbier of SEC Consult for the responsible
See CVE-2011-1948 for details.
be bypassed. This is a vulnerability in Products.PortalTransforms affecting
all versions of Plone using it, including 2.1 through 4.1. Thanks to
Daniel Berlin and Dan Bentley both of Google and Brian Peters
an independent researcher, for responsibly disclosing this independently of
See CVE-2011-1949 for details.
- Unauthorized data changes: One form allows users to edit the properties of
other users. This is a vulnerability in plone.app.users affecting Plone 4.0
This vulnerability was not disclosed responsibly to the security team.
See CVE-2011-1950 for details.
- Denial of service: A user can prevent other users from logging in. This is
a vulnerability in Products.PluggableAuthService affecting all versions of
Plone using it, including 2.5 through 4.1. Thanks to Alan Hoey of
Team Rubber for the responsible disclosure.
See PAS ticket #789858 for details.
This hotfix is supported on Plone 3 and 4. It is also known to work on Plone
2.5, and may work on older versions of Plone.
The fixes included here will be incorporated into subsequent releases of Plone,
so Plone 4.0.7, 4.1rc3, and greater should not require this hotfix.
- Fix a critical issue preventing correct functioning of one of the patches.
- Avoid trying to patch safe_html.StrippingParser if it is not present (as in
very old versions of PortalTransforms).
- Initial release
[Plone security team]
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.