CVE-2012-5501: High severity plone cms vulnerability
atdownload.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Images) stored on custom content types via a crafted URL.
Other sources
atdownload.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Images) stored on custom content types via a crafted URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5501?
CVE-2012-5501 is considered to be of medium severity due to its impact on data confidentiality.
How do I fix CVE-2012-5501?
To fix CVE-2012-5501, upgrade to Plone version 4.2.3 or 4.3 beta 1 or later.
What platforms are affected by CVE-2012-5501?
CVE-2012-5501 affects Plone versions prior to 4.2.3 and 4.3 before beta 1.
What types of data can be accessed due to CVE-2012-5501?
CVE-2012-5501 allows remote attackers to read arbitrary BLOBs, including files and images.
Is there a workaround for CVE-2012-5501?
There is no known workaround for CVE-2012-5501, so upgrading is the recommended solution.