CVE-2017-5524: Medium severity Plone plone vulnerability
Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtain sensitive information by leveraging the Python string format method.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/Ploneto a version that resolves this vulnerability.Fixed in 5.1b1 - Upgrade
Upgrade
pip/Ploneto a version that resolves this vulnerability.Fixed in 5.0.7 - Upgrade
Upgrade
pip/Ploneto a version that resolves this vulnerability.Fixed in 4.3.12
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5524?
CVE-2017-5524 is considered a medium severity vulnerability that allows remote attackers to bypass a sandbox protection mechanism.
How do I fix CVE-2017-5524?
To fix CVE-2017-5524, upgrade to Plone version 5.1b1 or later, or 5.0.7 or later, or 4.3.12 or later.
What software versions are affected by CVE-2017-5524?
CVE-2017-5524 affects Plone versions 4.x through 4.3.11 and 5.x through 5.0.6.
Can CVE-2017-5524 lead to data exposure?
Yes, CVE-2017-5524 can allow attackers to obtain sensitive information by exploiting the vulnerability.
Is there a patch available for CVE-2017-5524?
Yes, a hotfix is available and can be applied by updating to the relevant patched versions of Plone.