QID 982809
QID 982809: Python (pip) Security Update for plone.supermodel (GHSA-2c8c-84w2-j38j)
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2c8c-84w2-j38j for updates pertaining to this vulnerability.
Vendor References
- GHSA-2c8c-84w2-j38j -
github.com/advisories/GHSA-2c8c-84w2-j38j
CVEs related to QID 982809
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2c8c-84w2-j38j | Plone |
|
|
| GHSA-2c8c-84w2-j38j | plone.app.dexterity |
|
|
| GHSA-2c8c-84w2-j38j | plone.app.event |
|
|
| GHSA-2c8c-84w2-j38j | plone.app.theming |
|
|
| GHSA-2c8c-84w2-j38j | plone.supermodel |
|