CVE-2017-1000483: Medium severity plone cms vulnerability
Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.
Other sources
Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000483?
CVE-2017-1000483 is considered a moderate severity vulnerability due to potential unauthorized access to private content.
How do I fix CVE-2017-1000483?
To fix CVE-2017-1000483, upgrade to Plone version 5.1.0 or 4.3.16, as these versions contain the necessary patches.
Which versions of Plone are affected by CVE-2017-1000483?
CVE-2017-1000483 affects Plone versions from 2.5 to 5.1rc1, specifically versions 2.5.5 to 5.0.9.
What type of vulnerability is CVE-2017-1000483?
CVE-2017-1000483 is an access control vulnerability that allows unauthorized access to private content via the `str.format` method.
Is there a hotfix available for CVE-2017-1000483?
Yes, a hotfix was released to address CVE-2017-1000483, and it is included in the mentioned upgrades to Plone.