QID 982268
QID 982268: Python (pip) Security Update for Plone (GHSA-gc9g-67cq-p7v4)
Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-gc9g-67cq-p7v4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-gc9g-67cq-p7v4 -
github.com/advisories/GHSA-gc9g-67cq-p7v4
CVEs related to QID 982268
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gc9g-67cq-p7v4 | Plone |
|