First published: Thu Feb 08 2024(Updated: )
The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plone Plone | =5.2.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.