Information Exposure Affecting plone package, versions [,4.2.5)[4.3,4.3.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.33% (71st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-PLONE-40197
  • published1 Aug 2013
  • disclosed1 Aug 2013
  • creditUnknown

Introduced: 1 Aug 2013

CVE-2013-4191  (opens in a new tab)
CWE-264  (opens in a new tab)

Overview

plone is a Content Management System.

zip.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce access restrictions when including content in a zip archive, which allows remote attackers to obtain sensitive information by reading a generated archive.

CVSS Scores

version 3.1