CVE-2012-5487: Critical severity plone cms vulnerability
The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.
Other sources
The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5487?
CVE-2012-5487 is classified as critical because it allows authenticated users to execute arbitrary Python code due to improper sandbox restrictions.
How do I fix CVE-2012-5487?
To fix CVE-2012-5487, upgrade to Plone version 4.2.3 or later.
What versions are affected by CVE-2012-5487?
CVE-2012-5487 affects Plone versions prior to 4.2.3 and all versions from 1.0 to 4.1.
Who is impacted by CVE-2012-5487?
Users with certain authenticated privileges on vulnerable versions of Plone can exploit CVE-2012-5487.
What does CVE-2012-5487 allow attackers to do?
CVE-2012-5487 allows attackers to bypass Python sandbox restrictions and execute arbitrary Python code.