9.3

CVE-2011-4030

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Plone ≫ Cmfeditions Version 2.0a1
Plone ≫ Cmfeditions Version 2.0b1
Plone ≫ Cmfeditions Version 2.0b2
Plone ≫ Cmfeditions Version 2.0b3
Plone ≫ Cmfeditions Version 2.0b4
Plone ≫ Cmfeditions Version 2.0b5
Plone ≫ Cmfeditions Version 2.0b6
Plone ≫ Cmfeditions Version 2.0b7
Plone ≫ Cmfeditions Version 2.0b8
Plone ≫ Cmfeditions Version 2.0b9
Plone ≫ Plone Version 4.0
Plone ≫ Plone Version 4.0.1
Plone ≫ Plone Version 4.0.2
Plone ≫ Plone Version 4.0.3
Plone ≫ Plone Version 4.0.4
Plone ≫ Plone Version 4.0.5
Plone ≫ Plone Version 4.0.6.1
Plone ≫ Plone Version 4.0.7
Plone ≫ Plone Version 4.0.8
Plone ≫ Plone Version 4.0.9
Plone ≫ Plone Version 4.1
Plone ≫ Plone Version 4.2
Plone ≫ Plone Version 4.2a1
Plone ≫ Plone Version 4.2a2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.98% 0.784
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://plone.org/products/plone-hotfix/releases/20110928
Patch
http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zip
Patch
http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0
Patch
http://secunia.com/advisories/46323
http://www.securityfocus.com/bid/50287