CVE-2021-33509: Critical severity plone cms vulnerability
Published May 21, 2021
·Updated
Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.
Affected Software
2 affected componentsFixes available
pip/Plone<5.2.5
5.2.5
Plone plone<=5.2.4
Event History
May 21, 2021
CVE Published
via MITRE·09:33 PM
Data Sourced
via MITRE·09:33 PM
Description
Jun 15, 2021
Advisory Published
via GitHub·04:11 PM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-33509.
2
What is the severity of CVE-2021-33509?
The severity of CVE-2021-33509 is critical with a score of 9.9.
3
What is the affected software version of CVE-2021-33509?
The affected software version of CVE-2021-33509 is Plone up to 5.2.4.
4
How does CVE-2021-33509 allow remote authenticated managers to perform disk I/O?
CVE-2021-33509 allows remote authenticated managers to perform disk I/O by using crafted keyword arguments to the ReStructuredText transform in a Python script.
5
How can I fix CVE-2021-33509?
To fix CVE-2021-33509, it is recommended to apply the hotfix provided by Plone.