Description
Multiple unspecified vulnerabilities in (1) dataitems.py, (2) get.py, and (3) traverseName.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users with administrator access to a subtree to access nodes above the subtree via unknown vectors.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-0071 | Plone Privilege escalation due improper authorization |
Github GHSA |
GHSA-pwpq-632g-h49g | Plone Privilege escalation due improper authorization |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T16:38:01.823Z
Reserved: 2013-06-12T00:00:00.000Z
Link: CVE-2013-4189
No data.
Status : Deferred
Published: 2014-03-11T19:37:02.457
Modified: 2025-04-12T10:46:40.837
Link: CVE-2013-4189
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA