dist.plone.orgConfirmation
https://dist.plone.org/release/5.2.3/RELEASE-NOTES.txt CVE-2020-28735
SSRF attacks via tracebacks in Plone
Description
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
Description source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
PloneBrowse PyPI / Plone | GitHub Advisory | Before 5.2.3 · Fixed in 5.2.3 | affected |
plone.app.dexterityBrowse PyPI / plone.app.dexterity | GitHub Advisory | Before 2.6.8 · Fixed in 2.6.8 | affected |
plone.app.eventBrowse PyPI / plone.app.event | GitHub Advisory | Before 3.2.10 · Fixed in 3.2.10 | affected |
plone.app.themingBrowse PyPI / plone.app.theming | GitHub Advisory | Before 4.1.6 · Fixed in 4.1.6 | affected |
plone.supermodelBrowse PyPI / plone.supermodel | GitHub Advisory | Before 1.6.3 · Fixed in 1.6.3 | affected |
References
6github.com
https://github.com/advisories/GHSA-x7wf-5mjc-6x76 github.com
https://github.com/plone/Products.CMFPlone/issues/3209 github.com
https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2020-247.yaml nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-28735 misakikata.com
https://www.misakikata.com/codes/plone/python-en.html