PT-2024-1629 · Plone · Plone

Tomas Castro Rojas

·

Published

2024-01-25

·

Updated

2024-03-02

·

CVE-2024-23756

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Plone Docker version 5.2.13 (5221)
Description The issue is related to the absence of a mechanism to prevent unintended changes to resources when processing requests. This allows unauthenticated attackers to execute dangerous actions, such as uploading files to the server or deleting them, using the HTTP PUT and DELETE methods.
Recommendations For Plone Docker version 5.2.13 (5221), consider disabling the HTTP PUT and DELETE methods to prevent exploitation until a patch is available. Restrict access to the server to minimize the risk of unauthorized file uploads or deletions.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-01296
CVE-2024-23756

Affected Products

Plone