CVE-2013-4191
Plone 2.1-4.1 4.2.x-4.2.5 4.3.x-4.3.1 - Unauthenticated Sensitive Information Exposure via Zip Archive Generation
Title source: llmDescription
zip.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce access restrictions when including content in a zip archive, which allows remote attackers to obtain sensitive information by reading a generated archive.
References (4)
Core 4
Core References
Vendor Advisory x_refsource_confirm
http://plone.org/products/plone/security/advisories/20130618-announcement
Patch x_refsource_confirm
http://plone.org/products/plone-hotfix/releases/20130618
Mailing List mailing-list
x_refsource_mlist
http://seclists.org/oss-sec/2013/q3/261
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=978453
Scores
EPSS
0.0119
EPSS Percentile
64.7%
Details
CWE
CWE-264
Status
published
Products (50)
plone/plone
4.3
plone/plone
4.3.1
plone/plone
4.2
plone/plone
4.2.1
plone/plone
4.2.2
plone/plone
4.2.3
plone/plone
4.2.4
plone/plone
4.2.5
plone/plone
2.1
plone/plone
2.1.1
... and 40 more
Published
Mar 11, 2014
Tracked Since
Feb 18, 2026