8.8

CVE-2021-33926

Exploit

An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.10, 5.0.1, 5.0, 4.3.9, 4.3.8, 4.3.7, 4.3.6, 4.3.5, 4.3.4, 4.3.3, 4.3.20, 4 allows attacker to access sensitive information via the RSS feed protlet.

Data is provided by the National Vulnerability Database (NVD)
PlonePlone Version4.3
PlonePlone Version4.3.1
PlonePlone Version4.3.2
PlonePlone Version4.3.3
PlonePlone Version4.3.4
PlonePlone Version4.3.5
PlonePlone Version4.3.6
PlonePlone Version4.3.7
PlonePlone Version4.3.8
PlonePlone Version4.3.9
PlonePlone Version4.3.10
PlonePlone Version4.3.11
PlonePlone Version4.3.12
PlonePlone Version4.3.14
PlonePlone Version4.3.15
PlonePlone Version4.3.17
PlonePlone Version4.3.18
PlonePlone Version4.3.19
PlonePlone Version4.3.20
PlonePlone Version5.0 Update-
PlonePlone Version5.0 Updaterc1
PlonePlone Version5.0 Updaterc2
PlonePlone Version5.0 Updaterc3
PlonePlone Version5.0.1
PlonePlone Version5.0.2
PlonePlone Version5.0.3
PlonePlone Version5.0.4
PlonePlone Version5.0.5
PlonePlone Version5.0.6
PlonePlone Version5.0.7
PlonePlone Version5.0.8
PlonePlone Version5.0.9
PlonePlone Version5.0.10
PlonePlone Version5.1 Updatealpha2
PlonePlone Version5.1.1
PlonePlone Version5.1.2
PlonePlone Version5.1.4
PlonePlone Version5.1.5
PlonePlone Version5.1.6
PlonePlone Version5.1.7
PlonePlone Version5.1a1 Updatealpha1
PlonePlone Version5.1a2 Updatebeta4
PlonePlone Version5.1b2 Updatebeta3
PlonePlone Version5.1b3 Updatebeta2
PlonePlone Version5.1b4 Updaterc2
PlonePlone Version5.1rc1 Updaterc1
PlonePlone Version5.1rc2 Update-
PlonePlone Version5.2.0
PlonePlone Version5.2.1
PlonePlone Version5.2.2
PlonePlone Version5.2.3
PlonePlone Version5.2.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.21% 0.404
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.