CVE-2021-33510: SSRF
Published May 21, 2021
·Updated
Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a file.
Affected Software
2 affected components
pip/Plone<=5.2.4
Plone plone<=5.2.4
Event History
May 21, 2021
CVE Published
via MITRE·09:32 PM
Data Sourced
via MITRE·09:32 PM
Description
Jun 15, 2021
Advisory Published
via GitHub·04:11 PM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-33510.
2
What is the severity of CVE-2021-33510?
The severity of CVE-2021-33510 is medium with a CVSS score of 4.3.
3
How does CVE-2021-33510 affect Plone?
CVE-2021-33510 affects Plone versions up to and including 5.2.4.
4
What is the impact of CVE-2021-33510?
CVE-2021-33510 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, allowing them to read one line of a file.
5
Is there a fix available for CVE-2021-33510?
Yes, a fix for CVE-2021-33510 is available. Please refer to the official Plone security advisory for more information.