CVE-2021-33511: SSRF
Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-33511.
What is the severity of CVE-2021-33511?
The severity of CVE-2021-33511 is high with a severity value of 7.5.
What is the affected software?
The affected software is Plone version up to 5.2.4.
How does CVE-2021-33511 impact Plone?
CVE-2021-33511 allows SSRF (Server-Side Request Forgery) via the lxml parser, affecting Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.
Are there any references related to CVE-2021-33511?
Yes, you can find more information about CVE-2021-33511 at the following references: [Reference 1](http://www.openwall.com/lists/oss-security/2021/05/22/1) and [Reference 2](https://plone.org/security/hotfix/20210518/server-side-request-forgery-via-lxml-parser).