Description
The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.
References (5)
Core 5
Core References
Various Sources x_refsource_confirm
https://github.com/plone/Products.CMFPlone/blob/4.2.3/docs/CHANGES.txt
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/11/10/1
Vendor Advisory x_refsource_confirm
https://plone.org/products/plone/security/advisories/20121106/05
Issue Tracking x_refsource_confirm
https://bugs.launchpad.net/zope2/+bug/1079238
Patch x_refsource_confirm
https://plone.org/products/plone-hotfix/releases/20121106
Scores
EPSS
0.0057
EPSS Percentile
68.9%
Details
CWE
CWE-264
Status
published
Products (50)
plone/plone
1.0
plone/plone
1.0.1
plone/plone
1.0.2
plone/plone
1.0.3
plone/plone
1.0.4
plone/plone
1.0.5
plone/plone
1.0.6
plone/plone
2.0
plone/plone
2.0.1
plone/plone
2.0.2
... and 40 more
Published
Sep 30, 2014
Tracked Since
Feb 18, 2026