QID 982811
QID 982811: Python (pip) Security Update for plone.supermodel (GHSA-wq6x-g685-w5f2)
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-wq6x-g685-w5f2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-wq6x-g685-w5f2 -
github.com/advisories/GHSA-wq6x-g685-w5f2
CVEs related to QID 982811
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wq6x-g685-w5f2 | Plone |
|
|
| GHSA-wq6x-g685-w5f2 | plone.app.dexterity |
|
|
| GHSA-wq6x-g685-w5f2 | plone.app.event |
|
|
| GHSA-wq6x-g685-w5f2 | plone.app.theming |
|
|
| GHSA-wq6x-g685-w5f2 | plone.supermodel |
|