QID 981327

QID 981327: Python (pip) Security Update for Plone (GHSA-48vv-2pmq-9fvv)

Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 4.2 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-48vv-2pmq-9fvv for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981327

    Software Advisories
    Advisory ID Software Component Link
    GHSA-48vv-2pmq-9fvv Plone URL Logo github.com/advisories/GHSA-48vv-2pmq-9fvv
    GHSA-48vv-2pmq-9fvv Zope2 URL Logo github.com/advisories/GHSA-48vv-2pmq-9fvv