First published: Wed Dec 30 2020(Updated: )
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/plone.supermodel | <1.6.3 | 1.6.3 |
pip/plone.app.dexterity | <2.6.8 | 2.6.8 |
pip/plone.app.theming | <4.1.6 | 4.1.6 |
pip/plone.app.event | <3.2.10 | 3.2.10 |
pip/Plone | <5.2.3 | 5.2.3 |
Plone Plone | <5.2.3 | |
<5.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28735 is a vulnerability in Plone before version 5.2.3 that allows SSRF attacks via the tracebacks feature.
CVE-2020-28735 has a severity rating of 8.8, which is considered high.
Plone versions up to and excluding 5.2.3, plone.supermodel 1.6.3, plone.app.dexterity 2.6.8, plone.app.theming 4.1.6, plone.app.event 3.2.10 are affected by CVE-2020-28735.
To fix CVE-2020-28735, you should update Plone to version 5.2.3, plone.supermodel to 1.6.3, plone.app.dexterity to 2.6.8, plone.app.theming to 4.1.6, plone.app.event to 3.2.10.
You can find more information about CVE-2020-28735 at the following references: [1] [2] [3].