products.cmfcore@2.5.4 vulnerabilities

Zope Content Management Framework core components

  • latest version

    3.6

  • latest non vulnerable version

  • first published

    16 years ago

  • latest version published

    4 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the products.cmfcore package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Denial of Service (DoS)

    Affected versions of this package are vulnerable to Denial of Service (DoS) in the encodeFolderFilter() function in PortalFolder.py. The marshal module used on PortalFolder objects can cause a crash when supplied with very large inputs.

    How to fix Denial of Service (DoS)?

    Upgrade Products.CMFCore to version 2.7.1, 3.2 or higher.

    [,2.7.1)[3.0,3.2)