PT-2024-1348 · Plone · Plone

Tomas Castro Rojas

·

Published

2024-01-25

·

Updated

2026-01-20

·

CVE-2024-23055

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Plone Docker Official Image version 5.2.13 (5221)
Description The issue allows for remote code execution via improper validation of input by the HOST headers. This can be exploited by an attacker to execute arbitrary code by injecting code into the HOST header.
Recommendations For Plone Docker Official Image version 5.2.13 (5221), as a temporary workaround, consider restricting access to the HOST headers until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2024-00802
CVE-2024-23055

Affected Products

Plone