CVE-2012-5498: High severity plone cms vulnerability
A denial of service flaw was found in the way Plone, a user friendly and powerful content management system, performed processing of requests for certain collections. A remote attacker could provide a specially-crafted URL that, when processed would lead to excessive I/O and / or cache resources consumption.
References: [1] http://plone.org/products/plone/security/advisories/20121106/14 [2] http://plone.org/products/plone/security/advisories/20121106/
Relevant upstream HotFixes: [3] http://plone.org/products/plone-hotfix/releases/20121106
From the OSS post: [4] http://www.openwall.com/lists/oss-security/2012/11/07/4
the queryCatalog.py change from upstream HotFix is relevant to this issue.
Other sources
queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass caching and cause a denial of service via a crafted request to a collection.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5498?
CVE-2012-5498 is classified as a denial of service vulnerability that can lead to excessive I/O and cache resource consumption.
How do I fix CVE-2012-5498?
To fix CVE-2012-5498, upgrade to Plone version 4.3 or later.
What versions of Plone are affected by CVE-2012-5498?
CVE-2012-5498 affects Plone versions prior to 4.3 including 4.2.2 and earlier.
Can CVE-2012-5498 be exploited remotely?
Yes, CVE-2012-5498 can be exploited remotely by providing specially-crafted URLs.
What impact does CVE-2012-5498 have on my system?
CVE-2012-5498 can lead to a denial of service condition, potentially making your Plone application unresponsive.