CVE-2020-7938: High severity Plone plone vulnerability
plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/Ploneto a version that resolves this vulnerability.Fixed in 5.2.2 - Upgrade
Upgrade
pip/plone.restapito a version that resolves this vulnerability.Fixed in 6.2.1
Event History
Frequently Asked Questions
What is CVE-2020-7938?
CVE-2020-7938 is a vulnerability in plone.restapi in Plone 5.2.0 through 5.2.1 that allows users with a certain privilege level to escalate their privileges up to the highest level.
How severe is CVE-2020-7938?
CVE-2020-7938 has a severity rating of 8.8 out of 10.
How can I fix CVE-2020-7938?
To fix CVE-2020-7938, upgrade to plone.restapi version 6.2.1 or later.
Where can I find more information about CVE-2020-7938?
You can find more information about CVE-2020-7938 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-7938), [Plone Security Hotfix](https://plone.org/security/hotfix/20200121), [Plone Security Hotfix Privilege Escalation](https://plone.org/security/hotfix/20200121/privilege-escalation-when-plone-restapi-is-installed).
What is the common weakness enumeration (CWE) ID for CVE-2020-7938?
The CWE ID for CVE-2020-7938 is CWE-269.