Information disclosure in Plone - CVE-2016-4042

 

Information disclosure in Plone - CVE-2016-4042

Published: February 24, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU39622
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2016-4042
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Plone
Affected software:
Plone

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors.


How to mitigate CVE-2016-4042

Install update from vendor's website.

Sources