PT-2020-19862 · Plone · Plone

Damiano Esposito

·

Published

2020-01-23

·

Updated

2022-05-24

·

CVE-2020-7940

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Plone versions 4.3 through 5.2.0
Description The issue is related to missing password strength checks on some forms, allowing users to set weak passwords. This makes it easier for attackers to crack the passwords.
Recommendations For Plone versions 4.3 through 5.2.0, consider implementing custom password strength checks to enforce strong passwords until a patch is available. As a temporary workaround, restrict access to password change functionality to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7940
GHSA-CW58-GPGW-HWX2
PYSEC-2020-89

Affected Products

Plone