CVE-2012-5508

Plone <4.2.3, <4.3 beta - Info Disclosure

Title source: llm
STIX 2.1

Description

The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive the PRNG state for password resets via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6661 was assigned for the PRNG reseeding issue in Zope.

References (5)

Core 5

Scores

EPSS 0.0036
EPSS Percentile 58.0%

Details

CWE
CWE-200
Status published
Products (50)
plone/plone 1.0
plone/plone 1.0.1
plone/plone 1.0.2
plone/plone 1.0.3
plone/plone 1.0.4
plone/plone 1.0.5
plone/plone 1.0.6
plone/plone 2.0
plone/plone 2.0.1
plone/plone 2.0.2
... and 40 more
Published Nov 03, 2014
Tracked Since Feb 18, 2026