QID 980954
QID 980954: Python (pip) Security Update for Products.PlonePAS (GHSA-pq3x-96c3-xgjg)
The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pq3x-96c3-xgjg for updates pertaining to this vulnerability.
Vendor References
- GHSA-pq3x-96c3-xgjg -
github.com/advisories/GHSA-pq3x-96c3-xgjg
CVEs related to QID 980954
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pq3x-96c3-xgjg | Products.PlonePAS |
|