Description
Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) PloneHotfix20110720 for Plone 3.x allows attackers to gain privileges via unspecified vectors, related to a "highly serious vulnerability." NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-0720.
References (8)
Core 8
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/45056
Patch, Vendor Advisory x_refsource_confirm
http://plone.org/products/plone/security/advisories/20110622
Patch x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=718824
Patch mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/07/12/9
Patch mailing-list
x_refsource_mlist
https://mail.zope.org/pipermail/zope-announce/2011-June/002260.html
Patch, Vendor Advisory x_refsource_confirm
http://plone.org/products/plone-hotfix/releases/20110622
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/45111
Patch mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/07/04/6
Scores
EPSS
0.0201
EPSS Percentile
78.9%
Details
Status
published
Products (42)
plone/plone
3.0
plone/plone
3.0.1
plone/plone
3.0.2
plone/plone
3.0.3
plone/plone
3.0.4
plone/plone
3.0.5
plone/plone
3.0.6
plone/plone
3.1
plone/plone
3.1.1
plone/plone
3.1.2
... and 32 more
Published
Jul 19, 2011
Tracked Since
Feb 18, 2026