CVE-2012-5497: Infoleak
An information disclosure flaw was found in the way Plone, a user friendly and powerful content management system, enforced permissions check on membership database. A remote attacker could provide a specially-crafted URL that, when processed could allow the attacker to enumerate user account names.
References: [1] http://plone.org/products/plone/security/advisories/20121106/13 [2] http://plone.org/products/plone/security/advisories/20121106/
Relevant upstream HotFixes: [3] http://plone.org/products/plone-hotfix/releases/20121106
From the OSS post: [4] http://www.openwall.com/lists/oss-security/2012/11/07/4
the membershiptool.py change from upstream HotFix is relevant to this issue.
Other sources
membershiptool.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to enumerate user account names via a crafted URL.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5497?
CVE-2012-5497 is classified as a moderate severity vulnerability due to its potential to allow information disclosure.
How do I fix CVE-2012-5497?
To fix CVE-2012-5497, you should upgrade Plone to a version that is not affected, such as 4.3 or later.
What type of vulnerability is CVE-2012-5497?
CVE-2012-5497 is an information disclosure vulnerability that could allow enumeration of user account names.
Which versions of Plone are affected by CVE-2012-5497?
CVE-2012-5497 affects Plone versions up to and including 4.2.2 and various earlier versions from 1.0 to 4.2.
Can CVE-2012-5497 be exploited remotely?
Yes, CVE-2012-5497 can be exploited remotely through a specially crafted URL.