PT-2024-1629 · Plone · Plone
Tomas Castro Rojas
·
Published
2024-01-25
·
Updated
2024-03-02
·
CVE-2024-23756
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Plone Docker version 5.2.13 (5221)
Description
The issue is related to the absence of a mechanism to prevent unintended changes to resources when processing requests. This allows unauthenticated attackers to execute dangerous actions, such as uploading files to the server or deleting them, using the HTTP PUT and DELETE methods.
Recommendations
For Plone Docker version 5.2.13 (5221), consider disabling the HTTP PUT and DELETE methods to prevent exploitation until a patch is available. Restrict access to the server to minimize the risk of unauthorized file uploads or deletions.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plone