First published: Mon Sep 21 2015(Updated: )
A vulnerability that allows remote attackers to add a new member to a Plone site when registration is enabled, without acknowledgment of site administrator was found. Versions affected are Plone 3.x, 4.1.x, 4.2.x, <4.3.7, <5.0rc1. Upstream patch: <a href="https://github.com/zopefoundation/Products.CMFCore/commit/e1d981bfa14b664317285f0f36498f4be4a23406">https://github.com/zopefoundation/Products.CMFCore/commit/e1d981bfa14b664317285f0f36498f4be4a23406</a> CVE request: <a href="http://seclists.org/oss-sec/2015/q3/586">http://seclists.org/oss-sec/2015/q3/586</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/Plone | =5.0rc1 | |
pip/Plone | >=4.3a1<=4.3.6 | |
pip/Plone | >=4.2a1<=4.2.7 | |
pip/Plone | >=4.0a1<=4.0.10 | |
pip/Plone | >=3.3<=3.3.6 | |
pip/Products.CMFPlone | >=5.0a1<5.0rc2 | 5.0rc2 |
pip/Products.CMFPlone | >=3.3.0<4.3.6 | 4.3.7 |
Plone CMS | =3.3 | |
Plone CMS | =3.3.1 | |
Plone CMS | =3.3.2 | |
Plone CMS | =3.3.3 | |
Plone CMS | =3.3.4 | |
Plone CMS | =3.3.5 | |
Plone CMS | =3.3.6 | |
Plone CMS | =4.0 | |
Plone CMS | =4.0.1 | |
Plone CMS | =4.0.2 | |
Plone CMS | =4.0.3 | |
Plone CMS | =4.0.4 | |
Plone CMS | =4.0.5 | |
Plone CMS | =4.0.7 | |
Plone CMS | =4.0.8 | |
Plone CMS | =4.0.9 | |
Plone CMS | =4.0.10 | |
Plone CMS | =4.1 | |
Plone CMS | =4.1.1 | |
Plone CMS | =4.1.2 | |
Plone CMS | =4.1.3 | |
Plone CMS | =4.1.4 | |
Plone CMS | =4.1.5 | |
Plone CMS | =4.1.6 | |
Plone CMS | =4.2 | |
Plone CMS | =4.2.1 | |
Plone CMS | =4.2.2 | |
Plone CMS | =4.2.3 | |
Plone CMS | =4.2.4 | |
Plone CMS | =4.2.5 | |
Plone CMS | =4.2.6 | |
Plone CMS | =4.2.7 | |
Plone CMS | =4.3 | |
Plone CMS | =4.3.1 | |
Plone CMS | =4.3.2 | |
Plone CMS | =4.3.3 | |
Plone CMS | =4.3.4 | |
Plone CMS | =4.3.5 | |
Plone CMS | =4.3.6 | |
Plone CMS | =5.0-rc1 |
https://github.com/zopefoundation/Products.CMFCore/commit/e1d981bfa14b664317285f0f36498f4be4a23406
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7315 is classified as a medium severity vulnerability.
To fix CVE-2015-7315, update to Plone version 4.3.7 or 5.0rc2.
CVE-2015-7315 affects Plone versions 3.x, 4.1.x, 4.2.x, and below 4.3.7 and 5.0rc1.
If not addressed, CVE-2015-7315 allows remote attackers to add unauthorized users to a Plone site.
While specific exploit code is not publicly disclosed, the vulnerability allows for unauthorized access due to its nature.