Description
Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtain sensitive information by leveraging the Python string format method.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-0098 | Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtain sensitive information by leveraging the Python string format method. |
Github GHSA |
GHSA-p5wr-vp8g-q5p4 | Plone Sandbox Escape |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T15:04:15.030Z
Reserved: 2017-01-18T00:00:00.000Z
Link: CVE-2017-5524
No data.
Status : Deferred
Published: 2017-03-23T16:59:00.527
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-5524
OpenCVE Enrichment
No data.
EUVD
Github GHSA