CVE-2024-23054: Critical severity Plone Plone Docker Official Image vulnerability
Published Feb 5, 2024
·Updated
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).
Affected Software
1 affected component
Plone Plone Docker Official Image=5.2.13
Event History
Feb 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23054?
CVE-2024-23054 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-23054?
To fix CVE-2024-23054, upgrade to a patched version of the Plone Docker Official Image that addresses the vulnerable package.
3
What software is affected by CVE-2024-23054?
CVE-2024-23054 specifically affects Plone Docker Official Image version 5.2.13.
4
What type of vulnerability is CVE-2024-23054?
CVE-2024-23054 is an open-source software vulnerability that allows for remote code execution.
5
Is there a known exploit for CVE-2024-23054?
Yes, CVE-2024-23054 has been reported to potentially allow remote attackers to execute arbitrary code.