CVE-2020-7940: High severity Plone plone vulnerability
Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/Ploneto a version that resolves this vulnerability.Fixed in 5.2.2 - Upgrade
Upgrade
pip/Ploneto a version that resolves this vulnerability.Fixed in 5.1.7 - Upgrade
Upgrade
pip/Ploneto a version that resolves this vulnerability.Fixed in 4.3.20
Event History
Frequently Asked Questions
What is CVE-2020-7940?
CVE-2020-7940 is a vulnerability that allows users to set weak passwords on some forms in Plone 4.3 through 5.2.0, making them easier to crack.
How does CVE-2020-7940 affect Plone?
CVE-2020-7940 affects Plone versions 4.3 through 5.2.0.
What is the severity of CVE-2020-7940?
The severity of CVE-2020-7940 is high with a CVSS score of 7.5.
How can the CVE-2020-7940 vulnerability be fixed?
To fix the CVE-2020-7940 vulnerability, update to Plone version 5.2.2, 5.1.7, or 4.3.20.
Where can I find more information about CVE-2020-7940?
You can find more information about CVE-2020-7940 on the NIST NVD website and the Plone security hotfix page.