CVE-2013-4188

Plone 2.1-4.1 4.2.x-4.2.5 4.3.x-4.3.1 - Authenticated Denial of Service via Resource Retrieval

Title source: llm
STIX 2.1

Description

traverser.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote attackers with administrator privileges to cause a denial of service (infinite loop and resource consumption) via unspecified vectors related to "retrieving information for certain resources."

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2013/q3/261
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=978449

Scores

EPSS 0.0135
EPSS Percentile 68.5%

Details

CWE
CWE-399
Status published
Products (50)
plone/plone 4.3
plone/plone 4.3.1
plone/plone 2.1
plone/plone 2.1.1
plone/plone 2.1.2
plone/plone 2.1.3
plone/plone 2.1.4
plone/plone 2.5
plone/plone 2.5.1
plone/plone 2.5.2
... and 40 more
Published Mar 11, 2014
Tracked Since Feb 18, 2026