First published: Thu Jan 23 2020(Updated: )
Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/Plone | >=5.2.0<5.2.2 | 5.2.2 |
pip/Plone | >=5.0rc1<5.1.7 | 5.1.7 |
pip/Plone | >=4.3<4.3.20 | 4.3.20 |
Plone Plone | >=4.3.0<=5.2.0 | |
>=4.3.0<=5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7940 is a vulnerability that allows users to set weak passwords on some forms in Plone 4.3 through 5.2.0, making them easier to crack.
CVE-2020-7940 affects Plone versions 4.3 through 5.2.0.
The severity of CVE-2020-7940 is high with a CVSS score of 7.5.
To fix the CVE-2020-7940 vulnerability, update to Plone version 5.2.2, 5.1.7, or 4.3.20.
You can find more information about CVE-2020-7940 on the NIST NVD website and the Plone security hotfix page.