QID 982810
QID 982810: Python (pip) Security Update for plone.supermodel (GHSA-x7wf-5mjc-6x76)
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-x7wf-5mjc-6x76 for updates pertaining to this vulnerability.
Vendor References
- GHSA-x7wf-5mjc-6x76 -
github.com/advisories/GHSA-x7wf-5mjc-6x76
CVEs related to QID 982810
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x7wf-5mjc-6x76 | Plone |
|
|
| GHSA-x7wf-5mjc-6x76 | plone.app.dexterity |
|
|
| GHSA-x7wf-5mjc-6x76 | plone.app.event |
|
|
| GHSA-x7wf-5mjc-6x76 | plone.app.theming |
|
|
| GHSA-x7wf-5mjc-6x76 | plone.supermodel |
|