PYSEC-2017-58

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/plone/PYSEC-2017-58.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2017-58
Aliases
Published
2017-03-07T16:59:00Z
Modified
2024-04-29T11:41:30.214581Z
Summary
[none]
Details

Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators to read arbitrary files via a .. (dot dot) in the path parameter in a getFile action to Plone/++theme++barceloneta/@@plone.resourceeditor.filemanager-actions.

References

Affected packages

PyPI / plone

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0
Fixed
5.0.7
Introduced
4.2
Fixed
4.3.12

Affected versions

4.*

4.2
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3a1
4.3a2
4.3b1
4.3b2
4.3rc1
4.3
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.3.9
4.3.10
4.3.11

5.*

5.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6