First published: Thu Jan 23 2020(Updated: )
plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/plone.restapi | <6.2.1 | 6.2.1 |
Plone Plone | >=5.2.0<=5.2.1 | |
pip/Plone | >=5.2.0<5.2.2 | 5.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7938 is a vulnerability in plone.restapi in Plone 5.2.0 through 5.2.1 that allows users with a certain privilege level to escalate their privileges up to the highest level.
CVE-2020-7938 has a severity rating of 8.8 out of 10.
To fix CVE-2020-7938, upgrade to plone.restapi version 6.2.1 or later.
You can find more information about CVE-2020-7938 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-7938), [Plone Security Hotfix](https://plone.org/security/hotfix/20200121), [Plone Security Hotfix Privilege Escalation](https://plone.org/security/hotfix/20200121/privilege-escalation-when-plone-restapi-is-installed).
The CWE ID for CVE-2020-7938 is CWE-269.