First published: Wed Jun 26 2013(Updated: )
A security flaw was found in the way Plone, a user friendly and powerful content management system, restricted access to password change for unauthorized users. If from policy definition Plone user in question was not allowed to change their password, they (previously) could still reset / change the password via forgotten password email functionality.
Affected Software | Affected Version | How to fix |
---|---|---|
Plone CMS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-978480 is considered moderate due to the potential for unauthorized password changes.
To fix REDHAT-BUG-978480, ensure that the Plone CMS is updated to a version that addresses this security flaw.
REDHAT-BUG-978480 affects the Plone content management system.
Yes, REDHAT-BUG-978480 allows unauthorized users to change passwords when they should not have that permission.
Yes, REDHAT-BUG-978480 corresponds to CVE-2013-4198.