PT-2014-2762 · Plone Foundation · Plone
Jan Lieskovsky
·
Published
2014-03-11
·
Updated
2022-05-17
·
CVE-2013-4199
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Plone versions 2.1 through 4.1
Plone versions 4.2.x through 4.2.5
Plone versions 4.3.x through 4.3.1
Description
The issue allows remote authenticated users to cause a denial of service due to resource consumption. This occurs when a large zip archive is expanded, resulting in excessive resource usage. The scripts
cb decode.py and linkintegrity.py are involved in this issue.Recommendations
For Plone versions 2.1 through 4.1, update to a version outside of this range to resolve the issue.
For Plone versions 4.2.x through 4.2.5, update to a version outside of this range to resolve the issue.
For Plone versions 4.3.x through 4.3.1, update to a version outside of this range to resolve the issue.
Fix
DoS
RCE
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Plone