CVE-2012-5506: High severity plone cms vulnerability
Published Sep 30, 2014
·Updated
pythonscripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (infinite loop) via an RSS feed request for a folder the user does not have permission to access.
Affected Software
74 affected componentsFixes available
pip/plone>=4.3a1<4.3b1
4.3b1
pip/plone<4.2.3
4.2.3
Plone plone<=4.2.2
Plone plone=1.0
Plone plone=1.0.1
Plone plone=1.0.2
Plone plone=1.0.3
Plone plone=1.0.4
Plone plone=1.0.5
Plone plone=1.0.6
Plone plone=2.0
Plone plone=2.0.1
Plone plone=2.0.2
Plone plone=2.0.3
Plone plone=2.0.4
Plone plone=2.0.5
Plone plone=2.1
Plone plone=2.1.1
Plone plone=2.1.2
Plone plone=2.1.3
Plone plone=2.1.4
Plone plone=2.5
Plone plone=2.5.1
Plone plone=2.5.2
Plone plone=2.5.3
Plone plone=2.5.4
Plone plone=2.5.5
Plone plone=3.0
Plone plone=3.0.1
Plone plone=3.0.2
Plone plone=3.0.3
Plone plone=3.0.4
Plone plone=3.0.5
Plone plone=3.0.6
Plone plone=3.1
Plone plone=3.1.1
Plone plone=3.1.2
Plone plone=3.1.3
Plone plone=3.1.4
Plone plone=3.1.5.1
Plone plone=3.1.6
Plone plone=3.1.7
Plone plone=3.2
Plone plone=3.2.1
Plone plone=3.2.2
Plone plone=3.2.3
Plone plone=3.3
Plone plone=3.3.1
Plone plone=3.3.2
Plone plone=3.3.3
Plone plone=3.3.4
Plone plone=3.3.5
Plone plone=4.0
Plone plone=4.0.1
Plone plone=4.0.2
Plone plone=4.0.3
Plone plone=4.0.4
Plone plone=4.0.5
Plone plone=4.0.6.1
Plone plone=4.1
Plone plone=4.1.4
Plone plone=4.1.5
Plone plone=4.1.6
Plone plone=4.2
Plone plone=4.2-a1
Plone plone=4.2-a2
Plone plone=4.2-b1
Plone plone=4.2-b2
Plone plone=4.2-rc1
Plone plone=4.2-rc2
Plone plone=4.2.0.1
Plone plone=4.2.1
Plone plone=4.2.1.1
Plone plone=4.3
Remediation
Patch Available
Event History
Sep 30, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 17, 2022
Advisory Published
04:32 AM
Frequently Asked Questions
1
What is the severity of CVE-2012-5506?
CVE-2012-5506 has a moderate severity, causing a denial of service due to an infinite loop.
2
How do I fix CVE-2012-5506?
To fix CVE-2012-5506, upgrade Plone to version 4.2.3 or 4.3 beta 1 or later.
3
What versions of Plone are affected by CVE-2012-5506?
CVE-2012-5506 affects Plone versions before 4.2.3 and those in the 4.3 series before beta 1.
4
Can CVE-2012-5506 be exploited remotely?
Yes, CVE-2012-5506 can be exploited remotely via an unauthorized RSS feed request.
5
Is there a known workaround for CVE-2012-5506?
There is no known workaround for CVE-2012-5506 besides upgrading to the fixed versions.