Skip to main content

Plone security hotfix addressing CVE 2011-0720

Project description

This is a critical security hotfix which should be applied to the following versions of Plone:

  • Plone 4 <= 4.0.3

  • Plone 3 <= 3.3.5

  • Any version of Plone 2.5, 2.1, or 2.0

Additional information about the hotfix including frequently asked questions is available at http://plone.org/products/plone/security/advisories/cve-2011-0720

This hotfix applies the following modifications to improve Plone security:

  • Applies security declarations to some methods that were missing them, in order to address the vulnerability identified in CVE 2011-0720. The vulnerability discussed there affects Plone 2.5 and greater.

  • Applies security declarations and removal of docstrings to some additional methods that were identified by the Plone security team in an audit following the identification of CVE 2011-0720. This includes some methods present in Plone 2.0 and 2.1.

  • If necessary, applies a patch to the ZPublisher to fix an issue with the checking of whether traversed methods are publishable. This issue affects Plone 3.0 and higher, and is also available in the following new Zope2 releases: 2.10.13, 2.11.8, 2.12.15, 2.13.4

Installation

Installation instructions can be found at http://plone.org/products/plone-hotfix/releases/CVE-2011-0720

Changelog

1.0 (2011-02-08)

  • Initial release [Plone security team]

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

Products.PloneHotfix20110720-1.0.zip (9.2 kB view details)

Uploaded Source

File details

Details for the file Products.PloneHotfix20110720-1.0.zip.

File metadata

File hashes

Hashes for Products.PloneHotfix20110720-1.0.zip
Algorithm Hash digest
SHA256 5ffe39727a3117d2f4ae60b30771b2599c4ca92a624ffc7e1266b12f1b099e89
MD5 b2b03cf5f9d9819f8e13f7eb35684aa9
BLAKE2b-256 84f4da8915a0130f093e5b05e44e0d369348d23c25e2e9df91f8d635e72e89ab

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page