Skip to main content

Plone critical security hotfix addressing vulnerabilities in Zope and CMFEditions

Project description

This hotfix fixes the following vulnerabilities:

  • A vulnerability in CMFEditions where KwAsAttributes classes were publishable, exposing sub-objects to anonymous access. This vulnerability is found in CMFEditions 2.0a1 and up. CMFEditions 1.x and before are not vulnerable.

  • Zope vulnerability CVE 2011-3587. This vulnerability is found in Zope 2.12.x and 2.13.x. Zope 2.11 and before are not vulnerable.

    This Plone Hotfix applies the same fix as Products.Zope_Hotfix_CVE_2011_3587 and can co-exist with that patch.

This hotfix is supported on Plone 4.0 - 4.0.9, 4.1 and 4.2. Older versions of Plone (3.3.x and below) are not affected by the vulnerabilities and are not supported by this patch.

The fixes included here will be incorporated into subsequent releases of Plone, so Plone 4.0.10, 4.1.1, 4.2a3 and greater should not require this hotfix.

Installation

Installation instructions can be found at http://plone.org/products/plone-hotfix/releases/20110928

Changelog

1.1 (2011-10-04)

  • Fix URLs in the readme and setup.py. [mj]

1.0 (2011-10-04)

  • Initial release [Plone security team]

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

Products.PloneHotfix20110928-1.1.zip (6.9 kB view details)

Uploaded Source

File details

Details for the file Products.PloneHotfix20110928-1.1.zip.

File metadata

File hashes

Hashes for Products.PloneHotfix20110928-1.1.zip
Algorithm Hash digest
SHA256 ba793c9f2018ca71e29b21bdabab89587a5af00d38c08546cf16e551971c49e4
MD5 b7bb70dcfdaa4d023b83e0d66629f1e5
BLAKE2b-256 b484af368672fcb072b6576e9121e13c04b97f3509e74d5f6ebb8d8d948cd9e3

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page