CVE-2011-3587: Critical severity plone cms vulnerability
Plone upstream has published a pre-announcement about a security flaw, present in Zope v2.12.x and Zope v2.13.x, which could allow execution of arbitrary code by anonymous users. An authenticated attacker could provide a specially-crafted web page, which once visited by an unsuspecting Zope user would lead to arbitrary commands execution with the privileges of the Zope/Plone service.
References: [1] http://plone.org/products/plone/security/advisories/20110928 [2] http://secunia.com/advisories/46221/
Note: The vendor announced the final version of the advisory and the patch to be available at 2011-10-04 15:00 UTC at the following location: [3] http://plone.org/products/plone/security/advisories/20110928
Other sources
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p class in OFS/misc.py and the use of Python modules.
— GitHub
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p class in OFS/misc.py and the use of Python modules.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3587?
CVE-2011-3587 is classified as a high severity vulnerability due to its ability to allow remote attackers to execute arbitrary commands.
How do I fix CVE-2011-3587?
To mitigate CVE-2011-3587, upgrade to Zope version 2.13.10 or 2.12.20, or apply the appropriate Plone hotfix.
Which versions are affected by CVE-2011-3587?
CVE-2011-3587 affects Zope versions 2.12.x and 2.13.x, as well as Plone versions 4.0.x through 4.2a2.
Who is impacted by CVE-2011-3587?
Any user utilizing affected versions of Zope or Plone software for web applications is susceptible to the risks associated with CVE-2011-3587.
What is the nature of vulnerability in CVE-2011-3587?
CVE-2011-3587 is an unspecified vulnerability that relates to arbitrary command execution due to issues in the handling of Python modules.