Description
The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.
References (5)
Core 5
Core References
Patch x_refsource_confirm
http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/46323
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/50287
Patch x_refsource_confirm
http://plone.org/products/plone-hotfix/releases/20110928
Patch x_refsource_confirm
http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zip
Scores
EPSS
0.0197
EPSS Percentile
78.4%
Details
CWE
CWE-264
Status
published
Products (25)
plone/cmfeditions
2.0a1
plone/cmfeditions
2.0b1
plone/cmfeditions
2.0b2
plone/cmfeditions
2.0b3
plone/cmfeditions
2.0b4
plone/cmfeditions
2.0b5
plone/cmfeditions
2.0b6
plone/cmfeditions
2.0b7
plone/cmfeditions
2.0b8
plone/cmfeditions
2.0b9
... and 15 more
Published
Oct 10, 2011
Tracked Since
Feb 18, 2026