[oss-security] 20210522 Re: Plone security hotfix 20210518mailing list
http://www.openwall.com/lists/oss-security/2021/05/22/1 CVE-2021-33511
Server-Side Request Forgery in Plone
Description
Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PloneBrowse PyPI / Plone | GitHub Advisory | Through 5.2.4 | affected |
References
6github.com
https://github.com/advisories/GHSA-gc9g-67cq-p7v4 github.com
https://github.com/plone/Plone github.com
https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2021-83.yaml nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-33511 plone.org
https://plone.org/security/hotfix/20210518/server-side-request-forgery-via-lxml-parser