QID 995396
Date Published: 2023-09-25
QID 995396: Python (Pip) Security Update for plone (GHSA-hjp5-hv33-q58g)
Plone CMS 3.1.x uses invariant data (a client username and a server secret) when calculating an HMAC-SHA1 value for an authentication cookie, which makes it easier for remote attackers to gain permanent access to an account by sniffing the network.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-hjp5-hv33-q58g for updates and patch information.
Vendor References
- GHSA-hjp5-hv33-q58g -
github.com/advisories/GHSA-hjp5-hv33-q58g
CVEs related to QID 995396
Software Advisories
| Advisory ID | Software | Component | Link |
|---|