The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restrict access to internal methods, which allows remote attackers to obtain sensitive information via a crafted request.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2014-03-11T15:00:00

Updated: 2024-08-06T16:38:02.174Z

Reserved: 2013-06-12T00:00:00

Link: CVE-2013-4196

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2014-03-11T19:37:02.817

Modified: 2014-03-12T01:37:45.527

Link: CVE-2013-4196

cve-icon Redhat

No data.