Skip to main content

Plone critical security hotfix addressing multiple vulnerabilities

Project description

This hotfix fixes the following four vulnerabilities:

  1. Reflected XSS attack: A crafted URL can display arbitrary HTML output. This is a vulnerability in CMFPlone affecting all versions of Plone. Thanks to S. Streichsbier of SEC Consult for the responsible disclosure. See CVE-2011-1948 for details.

  2. Persistent XSS attack: Certain valid HTML will allow Javascript filtering to be bypassed. This is a vulnerability in Products.PortalTransforms affecting all versions of Plone using it, including 2.1 through 4.1. Thanks to Daniel Berlin and Dan Bentley both of Google and Brian Peters an independent researcher, for responsibly disclosing this independently of each other. See CVE-2011-1949 for details.

  3. Unauthorized data changes: One form allows users to edit the properties of other users. This is a vulnerability in plone.app.users affecting Plone 4.0 and 4.1. This vulnerability was not disclosed responsibly to the security team. See CVE-2011-1950 for details.

  4. Denial of service: A user can prevent other users from logging in. This is a vulnerability in Products.PluggableAuthService affecting all versions of Plone using it, including 2.5 through 4.1. Thanks to Alan Hoey of Team Rubber for the responsible disclosure. See PAS ticket #789858 for details.

This hotfix is supported on Plone 3 and 4. It is also known to work on Plone 2.5, and may work on older versions of Plone.

The fixes included here will be incorporated into subsequent releases of Plone, so Plone 4.0.7, 4.1rc3, and greater should not require this hotfix.

Installation

Installation instructions can be found at http://plone.org/products/plone-hotfix/releases/20110531

Changelog

1.0 (2011-06-01)

  • Initial release [Plone security team]

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

Products.PloneHotfix20110531-1.0.zip (10.4 kB view details)

Uploaded Source

File details

Details for the file Products.PloneHotfix20110531-1.0.zip.

File metadata

File hashes

Hashes for Products.PloneHotfix20110531-1.0.zip
Algorithm Hash digest
SHA256 806046c69b022a22884d518733eaec9af7d49a1aa792884c86b6bb6df0c913fd
MD5 b89091a42780341116eff7aa2fd03f4a
BLAKE2b-256 c76fca9b03cf03b5d69f2a81df37bbd660c65e4bde4db6cc10fa2b86fbc847b4

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page