[oss-security] 20200124 Re: Plone security hotfix 20200121mailing list
http://www.openwall.com/lists/oss-security/2020/01/24/1 CVE-2020-7936
Plone Open Redirect Vulnerability
Description
An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PloneBrowse PyPI / Plone | GitHub Advisory | 4.0 to < 4.3.20 · Fixed in 4.3.20 | affected |
| 5.0rc1 to < 5.1.7 · Fixed in 5.1.7 | affected | ||
| 5.2.0 to < 5.2.2 · Fixed in 5.2.2 | affected |
References
7github.com
https://github.com/plone/Plone github.com
https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2020-85.yaml nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-7936 plone.org
https://plone.org/security/hotfix/20200121 plone.org
https://plone.org/security/hotfix/20200121/an-open-redirection-on-the-login-form-and-possibly-other-places openwall.com
https://www.openwall.com/lists/oss-security/2020/01/22/1