REDHAT-BUG-718824: High severity plone cms vulnerability
It was reported [1] that Plone suffers from a vulnerability that can be exploited to bypass certain security restrictions. This is due to a vulnerable bundled version of Zope.
Plone 3.x users that backported the fix for CVE-2011-0720 (PloneHotfix20110720) are affected due to the vulnerability being inadvertently backported via the hotfix.
A new hotfix (20110622) is available [2] to correct the flaw.
[1] http://plone.org/products/plone/security/advisories/20110622 [2] http://plone.org/products/plone-hotfix/releases/20110622
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-718824?
The severity of REDHAT-BUG-718824 is categorized as high due to the potential for unauthorized access and security restrictions being bypassed.
How do I fix REDHAT-BUG-718824?
To fix REDHAT-BUG-718824, users should upgrade to a version of Plone that no longer uses the vulnerable bundled version of Zope.
Who is affected by REDHAT-BUG-718824?
REDHAT-BUG-718824 affects users of Plone 3.x who have not applied the necessary security fixes.
What security risks are associated with REDHAT-BUG-718824?
The security risks associated with REDHAT-BUG-718824 include potential unauthorized actions that bypass normal security controls in Plone.
Is REDHAT-BUG-718824 related to CVE-2011-0720?
Yes, REDHAT-BUG-718824 is related to CVE-2011-0720, as it stems from vulnerabilities in a bundled version of Zope that affects Plone.