6.5

CVE-2017-1000483

Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PlonePlone Version2.5.5
PlonePlone Version3.3
PlonePlone Version3.3.1
PlonePlone Version3.3.2
PlonePlone Version3.3.3
PlonePlone Version3.3.4
PlonePlone Version3.3.5
PlonePlone Version3.3.6
PlonePlone Version4.0
PlonePlone Version4.0.1
PlonePlone Version4.0.2
PlonePlone Version4.0.3
PlonePlone Version4.0.4
PlonePlone Version4.0.5
PlonePlone Version4.0.7
PlonePlone Version4.0.8
PlonePlone Version4.0.9
PlonePlone Version4.0.10
PlonePlone Version4.1
PlonePlone Version4.1.1
PlonePlone Version4.1.2
PlonePlone Version4.1.3
PlonePlone Version4.1.4
PlonePlone Version4.1.5
PlonePlone Version4.1.6
PlonePlone Version4.2
PlonePlone Version4.2.1
PlonePlone Version4.2.2
PlonePlone Version4.2.3
PlonePlone Version4.2.4
PlonePlone Version4.2.5
PlonePlone Version4.2.6
PlonePlone Version4.2.7
PlonePlone Version4.3
PlonePlone Version4.3.1
PlonePlone Version4.3.2
PlonePlone Version4.3.3
PlonePlone Version4.3.4
PlonePlone Version4.3.5
PlonePlone Version4.3.6
PlonePlone Version4.3.7
PlonePlone Version4.3.8
PlonePlone Version4.3.9
PlonePlone Version4.3.10
PlonePlone Version4.3.11
PlonePlone Version4.3.12
PlonePlone Version4.3.14
PlonePlone Version4.3.15
PlonePlone Version5.0
PlonePlone Version5.0 Updaterc1
PlonePlone Version5.0 Updaterc2
PlonePlone Version5.0 Updaterc3
PlonePlone Version5.0.1
PlonePlone Version5.0.2
PlonePlone Version5.0.3
PlonePlone Version5.0.4
PlonePlone Version5.0.5
PlonePlone Version5.0.6
PlonePlone Version5.0.7
PlonePlone Version5.0.8
PlonePlone Version5.0.9
PlonePlone Version5.1
PlonePlone Version5.1 Updatea1
PlonePlone Version5.1 Updatea2
PlonePlone Version5.1 Updateb2
PlonePlone Version5.1 Updateb3
PlonePlone Version5.1 Updateb4
PlonePlone Version5.1 Updaterc1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.523
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N