CVE-2011-4462: Input Validation
Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4462?
CVE-2011-4462 is considered a moderate severity vulnerability that can lead to denial of service due to CPU consumption.
How do I fix CVE-2011-4462?
To fix CVE-2011-4462, upgrade to Plone version 4.1.4 or later.
What is the impact of CVE-2011-4462?
The impact of CVE-2011-4462 allows remote attackers to trigger hash collisions, causing a denial of service.
Which versions of Plone are affected by CVE-2011-4462?
CVE-2011-4462 affects Plone versions up to and including 4.1.3, as well as earlier versions like 3.0 and 2.5.
Is there a known exploit for CVE-2011-4462?
As of the current date, there are no publicly available exploits specifically targeting CVE-2011-4462.