SB2017022408 - Multiple vulnerabilities in Plone



SB2017022408 - Multiple vulnerabilities in Plone

Published: February 24, 2017 Updated: August 8, 2020

Security Bulletin ID SB2017022408
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2016-4041)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webdav access via unspecified vectors.


2) Information disclosure (CVE-ID: CVE-2016-4042)

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors.


Remediation

Install update from vendor's website.