CVE-2020-28735: SSRF
Published Dec 30, 2020
·Updated
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
Affected Software
6 affected componentsFixes available
pip/plone.supermodel<1.6.3
1.6.3
pip/plone.app.dexterity<2.6.8
2.6.8
pip/plone.app.theming<4.1.6
4.1.6
pip/plone.app.event<3.2.10
3.2.10
pip/Plone<5.2.3
5.2.3
Plone plone<5.2.3
Remediation
Patch Available
Event History
Dec 30, 2020
CVE Published
via MITRE·06:38 PM
Data Sourced
via MITRE·06:38 PM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 7, 2021
Advisory Published
09:13 PM
Frequently Asked Questions
1
What is CVE-2020-28735?
CVE-2020-28735 is a vulnerability in Plone before version 5.2.3 that allows SSRF attacks via the tracebacks feature.
2
How severe is CVE-2020-28735?
CVE-2020-28735 has a severity rating of 8.8, which is considered high.
3
Which software versions are affected by CVE-2020-28735?
Plone versions up to and excluding 5.2.3, plone.supermodel 1.6.3, plone.app.dexterity 2.6.8, plone.app.theming 4.1.6, plone.app.event 3.2.10 are affected by CVE-2020-28735.
4
What is the remedy for CVE-2020-28735?
To fix CVE-2020-28735, you should update Plone to version 5.2.3, plone.supermodel to 1.6.3, plone.app.dexterity to 2.6.8, plone.app.theming to 4.1.6, plone.app.event to 3.2.10.
5
Where can I find more information about CVE-2020-28735?
You can find more information about CVE-2020-28735 at the following references: [1] [2] [3].