PT-2014-2334 · Plone+1 · Plone+1
Christian Heimes
·
Published
2014-09-30
·
Updated
2018-07-23
·
CVE-2012-5507
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Zope versions prior to 2.13.19
Plone versions prior to 4.2.3
Plone version 4.3 before beta 1
Description
The issue allows remote attackers to obtain passwords due to timing discrepancies in password validation. This is related to the AccessControl/AuthEncoding.py component in Zope.
Recommendations
For Zope versions prior to 2.13.19, update to version 2.13.19 or later.
For Plone versions prior to 4.2.3, update to version 4.2.3 or later.
For Plone version 4.3 before beta 1, update to beta 1 or later.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plone
Zope