CVE-2012-5489
Summary
| CVE | CVE-2012-5489 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-09-30 14:55:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Plone | Plone | 1.0 | All | All | All |
| Application | Plone | Plone | 1.0.1 | All | All | All |
| Application | Plone | Plone | 1.0.2 | All | All | All |
| Application | Plone | Plone | 1.0.3 | All | All | All |
| Application | Plone | Plone | 1.0.4 | All | All | All |
| Application | Plone | Plone | 1.0.5 | All | All | All |
| Application | Plone | Plone | 1.0.6 | All | All | All |
| Application | Plone | Plone | 2.0 | All | All | All |
| Application | Plone | Plone | 2.0.1 | All | All | All |
| Application | Plone | Plone | 2.0.2 | All | All | All |
| Application | Plone | Plone | 2.0.3 | All | All | All |
| Application | Plone | Plone | 2.0.4 | All | All | All |
| Application | Plone | Plone | 2.0.5 | All | All | All |
| Application | Plone | Plone | 2.1 | All | All | All |
| Application | Plone | Plone | 2.1.1 | All | All | All |
| Application | Plone | Plone | 2.1.2 | All | All | All |
| Application | Plone | Plone | 2.1.3 | All | All | All |
| Application | Plone | Plone | 2.1.4 | All | All | All |
| Application | Plone | Plone | 2.5 | All | All | All |
| Application | Plone | Plone | 2.5.1 | All | All | All |
| Application | Plone | Plone | 2.5.2 | All | All | All |
| Application | Plone | Plone | 2.5.3 | All | All | All |
| Application | Plone | Plone | 2.5.4 | All | All | All |
| Application | Plone | Plone | 2.5.5 | All | All | All |
| Application | Plone | Plone | 3.0 | All | All | All |
| Application | Plone | Plone | 3.0.1 | All | All | All |
| Application | Plone | Plone | 3.0.2 | All | All | All |
| Application | Plone | Plone | 3.0.3 | All | All | All |
| Application | Plone | Plone | 3.0.4 | All | All | All |
| Application | Plone | Plone | 3.0.5 | All | All | All |
| Application | Plone | Plone | 3.0.6 | All | All | All |
| Application | Plone | Plone | 3.1 | All | All | All |
| Application | Plone | Plone | 3.1.1 | All | All | All |
| Application | Plone | Plone | 3.1.2 | All | All | All |
| Application | Plone | Plone | 3.1.3 | All | All | All |
| Application | Plone | Plone | 3.1.4 | All | All | All |
| Application | Plone | Plone | 3.1.5.1 | All | All | All |
| Application | Plone | Plone | 3.1.6 | All | All | All |
| Application | Plone | Plone | 3.1.7 | All | All | All |
| Application | Plone | Plone | 3.2 | All | All | All |
| Application | Plone | Plone | 3.2.1 | All | All | All |
| Application | Plone | Plone | 3.2.2 | All | All | All |
| Application | Plone | Plone | 3.2.3 | All | All | All |
| Application | Plone | Plone | 3.3 | All | All | All |
| Application | Plone | Plone | 3.3.1 | All | All | All |
| Application | Plone | Plone | 3.3.2 | All | All | All |
| Application | Plone | Plone | 3.3.3 | All | All | All |
| Application | Plone | Plone | 3.3.4 | All | All | All |
| Application | Plone | Plone | 3.3.5 | All | All | All |
| Application | Plone | Plone | 4.0 | All | All | All |
| Application | Plone | Plone | 4.0.1 | All | All | All |
| Application | Plone | Plone | 4.0.2 | All | All | All |
| Application | Plone | Plone | 4.0.3 | All | All | All |
| Application | Plone | Plone | 4.0.4 | All | All | All |
| Application | Plone | Plone | 4.0.5 | All | All | All |
| Application | Plone | Plone | 4.0.6.1 | All | All | All |
| Application | Plone | Plone | 4.1 | All | All | All |
| Application | Plone | Plone | 4.1.4 | All | All | All |
| Application | Plone | Plone | 4.1.5 | All | All | All |
| Application | Plone | Plone | 4.1.6 | All | All | All |
| Application | Plone | Plone | 4.2 | All | All | All |
| Application | Plone | Plone | 4.2 | a1 | All | All |
| Application | Plone | Plone | 4.2 | a2 | All | All |
| Application | Plone | Plone | 4.2 | b1 | All | All |
| Application | Plone | Plone | 4.2 | b2 | All | All |
| Application | Plone | Plone | 4.2 | rc1 | All | All |
| Application | Plone | Plone | 4.2 | rc2 | All | All |
| Application | Plone | Plone | 4.2.0.1 | All | All | All |
| Application | Plone | Plone | 4.2.1 | All | All | All |
| Application | Plone | Plone | 4.2.1.1 | All | All | All |
| Application | Plone | Plone | 4.3 | All | All | All |
| Application | Plone | Plone | All | All | All | All |
| Application | Zope | Zope | 2.10.3 | All | All | All |
| Application | Zope | Zope | 2.10.8 | All | All | All |
| Application | Zope | Zope | 2.11.0 | All | All | All |
| Application | Zope | Zope | 2.11.1 | All | All | All |
| Application | Zope | Zope | 2.11.2 | All | All | All |
| Application | Zope | Zope | 2.11.3 | All | All | All |
| Application | Zope | Zope | 2.13.0 | All | All | All |
| Application | Zope | Zope | 2.13.1 | All | All | All |
| Application | Zope | Zope | 2.13.2 | All | All | All |
| Application | Zope | Zope | 2.13.3 | All | All | All |
| Application | Zope | Zope | 2.13.4 | All | All | All |
| Application | Zope | Zope | 2.13.5 | All | All | All |
| Application | Zope | Zope | 2.13.6 | All | All | All |
| Application | Zope | Zope | 2.13.7 | All | All | All |
| Application | Zope | Zope | 2.13.8 | All | All | All |
| Application | Zope | Zope | 2.13.9 | All | All | All |
| Application | Zope | Zope | 2.5.1 | All | All | All |
| Application | Zope | Zope | 2.6.1 | All | All | All |
| Application | Zope | Zope | 2.6.4 | All | All | All |
| Application | Zope | Zope | 2.7.0 | All | All | All |
| Application | Zope | Zope | 2.7.3 | All | All | All |
| Application | Zope | Zope | 2.7.4 | All | All | All |
| Application | Zope | Zope | 2.7.5 | All | All | All |
| Application | Zope | Zope | 2.7.6 | All | All | All |
| Application | Zope | Zope | 2.7.7 | All | All | All |
| Application | Zope | Zope | 2.7.8 | All | All | All |
| Application | Zope | Zope | 2.8.1 | All | All | All |
| Application | Zope | Zope | 2.8.4 | All | All | All |
| Application | Zope | Zope | 2.8.6 | All | All | All |
| Application | Zope | Zope | 2.8.8 | All | All | All |
| Application | Zope | Zope | 2.9.2 | All | All | All |
| Application | Zope | Zope | 2.9.3 | All | All | All |
| Application | Zope | Zope | 2.9.4 | All | All | All |
| Application | Zope | Zope | 2.9.5 | All | All | All |
| Application | Zope | Zope | 2.9.6 | All | All | All |
| Application | Zope | Zope | 2.9.7 | All | All | All |
| Application | Zope | Zope | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Plone Hotfix 20121106 — Plone CMS: Open Source Content Management | af854a3a-2127-422b-91ae-364da2661108 | plone.org | Patch |
| Partial restricted Python sandbox escape — Plone CMS: Open Source Content Management | af854a3a-2127-422b-91ae-364da2661108 | plone.org | Vendor Advisory |
| Bug #1079238 “App.Undo.UndoSupport.get_request_var_or_attr expos...” : Bugs : Zope 2 | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | |
| oss-security - Re: Re: CVE Request - Zope / Plone: Multiple vectors corrected within 20121106 fix | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Products.CMFPlone/CHANGES.txt at 4.2.3 · plone/Products.CMFPlone · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981211 Python (pip) Security Update for Plone (GHSA-879r-7f3w-8jj3)