CVE-2013-4196
Summary
| CVE | CVE-2013-4196 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-03-11 19:37:02 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restrict access to internal methods, which allows remote attackers to obtain sensitive information via a crafted request. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Plone | Plone | 2.1 | All | All | All |
| Application | Plone | Plone | 2.1.1 | All | All | All |
| Application | Plone | Plone | 2.1.2 | All | All | All |
| Application | Plone | Plone | 2.1.3 | All | All | All |
| Application | Plone | Plone | 2.1.4 | All | All | All |
| Application | Plone | Plone | 2.5 | All | All | All |
| Application | Plone | Plone | 2.5.1 | All | All | All |
| Application | Plone | Plone | 2.5.2 | All | All | All |
| Application | Plone | Plone | 2.5.3 | All | All | All |
| Application | Plone | Plone | 2.5.4 | All | All | All |
| Application | Plone | Plone | 2.5.5 | All | All | All |
| Application | Plone | Plone | 3.0 | All | All | All |
| Application | Plone | Plone | 3.0.1 | All | All | All |
| Application | Plone | Plone | 3.0.2 | All | All | All |
| Application | Plone | Plone | 3.0.3 | All | All | All |
| Application | Plone | Plone | 3.0.4 | All | All | All |
| Application | Plone | Plone | 3.0.5 | All | All | All |
| Application | Plone | Plone | 3.0.6 | All | All | All |
| Application | Plone | Plone | 3.1 | All | All | All |
| Application | Plone | Plone | 3.1.1 | All | All | All |
| Application | Plone | Plone | 3.1.2 | All | All | All |
| Application | Plone | Plone | 3.1.3 | All | All | All |
| Application | Plone | Plone | 3.1.4 | All | All | All |
| Application | Plone | Plone | 3.1.5.1 | All | All | All |
| Application | Plone | Plone | 3.1.6 | All | All | All |
| Application | Plone | Plone | 3.1.7 | All | All | All |
| Application | Plone | Plone | 3.2 | All | All | All |
| Application | Plone | Plone | 3.2.1 | All | All | All |
| Application | Plone | Plone | 3.2.2 | All | All | All |
| Application | Plone | Plone | 3.2.3 | All | All | All |
| Application | Plone | Plone | 3.3 | All | All | All |
| Application | Plone | Plone | 3.3.1 | All | All | All |
| Application | Plone | Plone | 3.3.2 | All | All | All |
| Application | Plone | Plone | 3.3.3 | All | All | All |
| Application | Plone | Plone | 3.3.4 | All | All | All |
| Application | Plone | Plone | 3.3.5 | All | All | All |
| Application | Plone | Plone | 4.0 | All | All | All |
| Application | Plone | Plone | 4.0.1 | All | All | All |
| Application | Plone | Plone | 4.0.2 | All | All | All |
| Application | Plone | Plone | 4.0.3 | All | All | All |
| Application | Plone | Plone | 4.0.4 | All | All | All |
| Application | Plone | Plone | 4.0.5 | All | All | All |
| Application | Plone | Plone | 4.0.6.1 | All | All | All |
| Application | Plone | Plone | 4.1 | All | All | All |
| Application | Plone | Plone | 4.2 | All | All | All |
| Application | Plone | Plone | 4.2.1 | All | All | All |
| Application | Plone | Plone | 4.2.2 | All | All | All |
| Application | Plone | Plone | 4.2.3 | All | All | All |
| Application | Plone | Plone | 4.2.4 | All | All | All |
| Application | Plone | Plone | 4.2.5 | All | All | All |
| Application | Plone | Plone | 4.3 | All | All | All |
| Application | Plone | Plone | 4.3.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-sec: Re: CVE Request -- Plone: 20130618 Hotfix (multiple vectors) | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Security vulnerability announcement: 20130618 - Multiple vectors — Plone CMS: Open Source Content Management | af854a3a-2127-422b-91ae-364da2661108 | plone.org | Vendor Advisory |
| 978475 – (CVE-2013-4196) CVE-2013-4196 plone: Multiple information exposure flaws via certain object methods (objectmanager.py) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Plone Hotfix 20130618 — Plone CMS: Open Source Content Management | af854a3a-2127-422b-91ae-364da2661108 | plone.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.