CVE-2024-22889: High severity plone cms vulnerability
Published Mar 5, 2024
·Updated
Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.
Affected Software
2 affected components
pip/Plone<=6.0.9
Plone plone=6.0.9
Event History
Mar 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Mar 6, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·12:31 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-22889?
CVE-2024-22889 is classified as a critical vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2024-22889?
To remediate CVE-2024-22889, upgrade Plone to version 6.0.10 or later, which includes a patch for the access control issue.
3
What versions of Plone are affected by CVE-2024-22889?
CVE-2024-22889 affects Plone version 6.0.9 and earlier.
4
What can attackers do with CVE-2024-22889?
Attackers can exploit CVE-2024-22889 to remotely view and list all files hosted on the affected Plone website.
5
Is there a workaround for CVE-2024-22889?
There are no recommended workarounds; the only solution is to upgrade to a patched version.