QID 980961
QID 980961: Python (pip) Security Update for Plone (GHSA-pcwm-8jc3-qxvj)
Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pcwm-8jc3-qxvj for updates pertaining to this vulnerability.
Vendor References
- GHSA-pcwm-8jc3-qxvj -
github.com/advisories/GHSA-pcwm-8jc3-qxvj
CVEs related to QID 980961
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pcwm-8jc3-qxvj | Plone |
|