Permissions, Privileges, and Access Controls in Plone - CVE-2013-4196

 

Permissions, Privileges, and Access Controls in Plone - CVE-2013-4196

Published: March 11, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41938
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2013-4196
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Plone
Affected software:
Plone

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restrict access to internal methods, which allows remote attackers to obtain sensitive information via a crafted request.


How to mitigate CVE-2013-4196

Install update from vendor's website.

Sources