PT-2011-3915 · Zope+1 · Zope+1
Vincent Danen
·
Published
2011-07-19
·
Updated
2018-07-23
·
CVE-2011-2528
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Zope versions 2.12.x through 2.12.18
Zope versions 2.13.x through 2.13.7
PloneHotfix20110720 for Plone 3.x
Description
The issue allows attackers to gain privileges via unspecified vectors, related to a highly serious vulnerability. This vulnerability exists because of an incorrect fix for a previous issue.
Recommendations
For Zope versions 2.12.x through 2.12.18, update to version 2.12.19 or later.
For Zope versions 2.13.x through 2.13.7, update to version 2.13.8 or later.
For Plone 3.x with PloneHotfix20110720 applied, consider removing the hotfix and applying a corrected fix to mitigate the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Plone
Zope