CVE-2016-4041: High severity Plone plone vulnerability
Published Feb 24, 2017
·Updated
Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webdav access via unspecified vectors.
Affected Software
47 affected componentsFixes available
pip/Plone=5.1a1
5.1a2
pip/Plone>=5.0<5.0.5
5.0.5
pip/Plone>=3.3<4.3.10
4.3.10
Plone plone=4.0
Plone plone=4.0.1
Plone plone=4.0.2
Plone plone=4.0.3
Plone plone=4.0.4
Plone plone=4.0.5
Plone plone=4.0.7
Plone plone=4.0.8
Plone plone=4.0.9
Plone plone=4.0.10
Plone plone=4.1
Plone plone=4.1.1
Plone plone=4.1.2
Plone plone=4.1.3
Plone plone=4.1.4
Plone plone=4.1.5
Plone plone=4.1.6
Plone plone=4.2
Plone plone=4.2.1
Plone plone=4.2.2
Plone plone=4.2.3
Plone plone=4.2.4
Plone plone=4.2.5
Plone plone=4.2.6
Plone plone=4.2.7
Plone plone=4.3
Plone plone=4.3.1
Plone plone=4.3.2
Plone plone=4.3.3
Plone plone=4.3.4
Plone plone=4.3.5
Plone plone=4.3.6
Plone plone=4.3.7
Plone plone=4.3.8
Plone plone=4.3.9
Plone plone=5.0
Plone plone=5.0-a1
Plone plone=5.0-rc1
Plone plone=5.0-rc2
Plone plone=5.0-rc3
Plone plone=5.0.1
Plone plone=5.0.2
Plone plone=5.0.3
Plone plone=5.0.4
Event History
Feb 24, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:59 PM
DescriptionSeverityWeaknessAffected Software
May 17, 2022
Advisory Published
via GitHub·02:57 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-4041?
CVE-2016-4041 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2016-4041?
To fix CVE-2016-4041, upgrade Plone to version 5.0.5 or 4.3.10, or apply the available patches.
3
Which versions of Plone are affected by CVE-2016-4041?
CVE-2016-4041 affects Plone versions 4.0 through 5.1a1.
4
What type of attack does CVE-2016-4041 enable?
CVE-2016-4041 allows remote attackers to gain unauthorized access to WebDAV functionalities.
5
Is there a known exploit for CVE-2016-4041?
Yes, CVE-2016-4041 can be exploited through unspecified vectors that target the lack of security declarations.