CVE-2012-5489: Medium severity plone cms vulnerability
The App.Undo.UndoSupport.getrequestvarorattr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5489?
CVE-2012-5489 has been classified as a moderate severity vulnerability that allows remote authenticated users to access restricted attributes.
How do I fix CVE-2012-5489?
To fix CVE-2012-5489, upgrade to Plone version 4.2.3 or later, or Zope version 2.13.11 or later.
Which versions of Plone are affected by CVE-2012-5489?
All versions of Plone before 4.2.3, as well as various 4.3 beta versions, are affected by CVE-2012-5489.
How does CVE-2012-5489 affect Zope?
CVE-2012-5489 affects Zope versions before 2.12.21 and 3.13.x before 2.13.11, allowing unauthorized access to certain attributes.
Can CVE-2012-5489 be exploited remotely?
Yes, CVE-2012-5489 can be exploited remotely by authenticated users to gain access to restricted attributes.