QID 995373
Date Published: 2023-09-25
QID 995373: Python (Pip) Security Update for plone (GHSA-hf26-vvmx-x8c8)
Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled objects for the (1) statusmessages or (2) linkintegrity module, which the module unpickles and executes.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-hf26-vvmx-x8c8 for updates and patch information.
Vendor References
- GHSA-hf26-vvmx-x8c8 -
github.com/advisories/GHSA-hf26-vvmx-x8c8
CVEs related to QID 995373
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hf26-vvmx-x8c8 | plone |
|