Security vulnerability: 20151208 — Plone CMS: Open Source Content Management
"Announcement of Plone releases and security-related notifications. Recommended subscription for all Plone developers and site admins." <[email protected]> Tue, 8 Dec 2015 09:19:56 -0600
| Newsgroups | gmane.comp.web.zope.plone.announce |
|---|---|
| Message-ID | <D2094A3B-E769-4A51-9704-42FF6CA9DE45__36304.6190738261$1449668754$gmane$org@plone.org> |
--===============6506724317865230549== Content-Type: multipart/alternative; boundary="Apple-Mail=_278BAFC8-5A45-4D27-9FB0-D65980DE5D0F" --Apple-Mail=_278BAFC8-5A45-4D27-9FB0-D65980DE5D0F Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 > = https://plone.org/products/plone/security/advisories/20151208-announcement= = <https://plone.org/products/plone/security/advisories/20151208-announcemen= t> Security vulnerability: 20151208 Patches to Plone for unauthorized disclosure of registered user = information Versions Affected: All current Plone versions.=20 Versions Not Affected: None. Nature of vulnerability: Allows unauthorized disclosure of registered = user information The patch can be added to buildouts as Products.PloneHotfix20151208 = (available from pypi.python.org = <https://pypi.python.org/pypi?%3Aaction=3Dsearch&term=3DProducts.PloneHotf= ix20151208&submit=3Dsearch>) or downloaded from Plone.org = <https://plone.org/products/plone-hotfix/releases/20151208> This patch is compatible with all supported Plone versions (i.e. Plone = 4, Plone 5). It may work on earlier versions of Plone, but as these are = officially unsupported they have not undergone the same level of testing = with the patch. Installation Full installation instructions are available on the HotFix release page = <https://plone.org/products/plone-hotfix/releases/20151208>. Extra Help If you do not have in-house server administrators or a website = maintenance service agreement, you can find consulting companies at = plone.com/providers=C2=A0 <http://plone.com/providers>and = plone.org/support/network=C2=A0 <https://plone.org/support/network>. There is also free support=C2=A0 <https://plone.org/support>available = online via the Plone IRC channel <http://plone.org/support> and the = Plone community forum <http://community.plone.org/>. Thanks The Plone Security Team is grateful to Giovanni Monteiro Calanzani and = Glauter de Sousa Vilela, who reported the vulnerability. Questions and Answers Q. What is involved in applying the patch?=20 A. Patches are made available as tarball-style archives that may be = unpacked into the =E2=80=9Cproducts=E2=80=9D folder of a buildout = installation and as Python packages that may be installed by editing a = buildout configuration file and running buildout. Patching is generally = easy and quick to accomplish. Q: My site is highly visible and mission-critical. I hear the patch has = already been developed. Can I get the fix before the release date?=20 A: Plone patches are always made available to all users at the same = time. There are no exceptions. General questions about this announcement, Plone patching procedures, = and availability of support may be addressed to the Plone support = forums=C2=A0 <https://plone.org/support>. If you have specific questions = about this vulnerability or its handling, contact the Plone Security = Team=C2=A0 <mailto:security-z4DKO/[email protected]>directly. To report potentially security-related issues, e-mail the Plone Security = Team directly at security-z4DKO/[email protected] <mailto:security-z4DKO/[email protected]>. We are = always happy to credit individuals and companies who make responsible = disclosures. The Plone Security Team is an all-volunteer team. If you'd like to help = the team, as a developer, a tester, or as a financial sponsor, please = email the team at security-z4DKO/[email protected] = <mailto:security-z4DKO/[email protected]?subject=3Dsupport%20for%20the%20Plone%20Securit= y%20Team>. Information for Vulnerability Database Maintainers We have already applied for CVE numbers for these issues. Further = information on individual vulnerabilities (including CVSS scores, CWE = identifiers and summaries) is available at the full vulnerability list = <https://plone.org/products/plone/security/>= --Apple-Mail=_278BAFC8-5A45-4D27-9FB0-D65980DE5D0F Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 <html><head><meta http-equiv=3D"Content-Type" content=3D"text/html = charset=3Dutf-8"><base></head><body style=3D"word-wrap: break-word; = -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" = class=3D""><base class=3D""><div = class=3D"Apple-Mail-URLShareUserContentTopClass"><br class=3D""></div><div= class=3D"Apple-Mail-URLShareWrapperClass" style=3D"position: relative = !important;"><blockquote type=3D"cite" style=3D"border-left-style: none; = color: inherit; padding: inherit; margin: inherit;" class=3D""><a = href=3D"https://plone.org/products/plone/security/advisories/20151208-anno= uncement" = class=3D"">https://plone.org/products/plone/security/advisories/20151208-a= nnouncement</a><br class=3D""></blockquote><br class=3D""></div><div = class=3D"Apple-Mail-URLShareWrapperClass" style=3D"position: relative = !important;"><h1 id=3D"parent-fieldname-title" = class=3D"documentFirstHeading" style=3D"margin: 0px; padding: 0px; = font-size: 1.625em; font-family: 'Helvetica Neue', Arial, FreeSans, = sans-serif; line-height: 32.5px; letter-spacing: -1px;">Security = vulnerability: 20151208</h1><div id=3D"viewlet-below-content-title" = style=3D"margin: 0px; padding: 0px; font-family: Arial, FreeSans, = sans-serif; font-size: 16px;" class=3D""><div class=3D"RatingViewlet" = style=3D"margin: 0px; padding: 0px;"></div></div><div = id=3D"parent-fieldname-description" class=3D"documentDescription" = style=3D"margin: 0px 0px 1em; padding: 0px; color: gray !important; = font-weight: bold !important; font-size: 1em !important; line-height: = normal !important; font-family: 'Helvetica Neue', Arial, FreeSans, = sans-serif !important;">Patches to Plone for unauthorized disclosure of = registered user information</div><div id=3D"viewlet-above-content-body" = style=3D"margin: 0px; padding: 0px; font-family: Arial, FreeSans, = sans-serif; font-size: 16px;" class=3D""></div><div id=3D"content-core" = style=3D"margin: 0px; padding: 0px; font-family: Arial, FreeSans, = sans-serif; font-size: 16px;" class=3D""><div id=3D"parent-fieldname-text"= class=3D"plain" style=3D"margin: 0px; padding: 0px;"><p style=3D"margin: = 0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" = class=3D""><b style=3D"margin: 0px; padding: 0px;" class=3D"">Versions = Affected: </b>All current Plone versions. <br style=3D"margin: = 0px; padding: 0px;" class=3D""><b style=3D"margin: 0px; padding: 0px;" = class=3D"">Versions Not Affected: </b>None.</p><p style=3D"margin: = 0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" = class=3D""><strong style=3D"margin: 0px; padding: 0px;" class=3D"">Nature = of vulnerability:</strong> Allows unauthorized disclosure of = registered user information</p><p style=3D"margin: 0px 0px 1em; padding: = 0px; font-size: 13px; line-height: 1.5em;" class=3D"">The patch can be = added to buildouts as Products.PloneHotfix20151208 (available = from <a class=3D"external-link" = href=3D"https://pypi.python.org/pypi?%3Aaction=3Dsearch&term=3DProduct= s.PloneHotfix20151208&submit=3Dsearch" target=3D"_self" title=3D"" = style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: = none; color: rgb(66, 117, 151); border-bottom-width: 1px; = border-bottom-style: solid; border-bottom-color: rgb(204, 204, = 204);">pypi.python.org</a>) or downloaded from <a title=3D"" = href=3D"https://plone.org/products/plone-hotfix/releases/20151208" = class=3D"external-link" target=3D"_self" style=3D"margin: 0px; padding: = 0px; outline: none; text-decoration: none; color: rgb(66, 117, 151); = border-bottom-width: 1px; border-bottom-style: solid; = border-bottom-color: rgb(204, 204, 204);">Plone.org</a></p><p = style=3D"margin: 0px 0px 1em; padding: 0px; font-size: 13px; = line-height: 1.5em;" class=3D"">This patch is compatible with all = supported Plone versions (i.e. Plone 4, Plone 5). It may work on earlier = versions of Plone, but as these are officially unsupported they have not = undergone the same level of testing with the patch.</p><h3 = style=3D"margin: 0.5em 0px 0px; padding: 0px; font-size: 1.125em; = font-family: 'Helvetica Neue', Arial, FreeSans, sans-serif; line-height: = 22.5px; color: rgb(68, 68, 68);" class=3D"">Installation</h3><p = style=3D"margin: 0px 0px 1em; padding: 0px; font-size: 13px; = line-height: 1.5em;" class=3D"">Full installation instructions are = available on <a title=3D"" = href=3D"https://plone.org/products/plone-hotfix/releases/20151208" = class=3D"external-link" target=3D"_self" style=3D"margin: 0px; padding: = 0px; outline: none; text-decoration: none; color: rgb(66, 117, 151); = border-bottom-width: 1px; border-bottom-style: solid; = border-bottom-color: rgb(204, 204, 204);">the HotFix release = page</a>.</p><h3 style=3D"margin: 0.5em 0px 0px; padding: 0px; = font-size: 1.125em; font-family: 'Helvetica Neue', Arial, FreeSans, = sans-serif; line-height: 22.5px; color: rgb(68, 68, 68);" class=3D"">Extra= Help</h3><p style=3D"margin: 0px 0px 1em; padding: 0px; font-size: = 13px; line-height: 1.5em;" class=3D"">If you do not have in-house server = administrators or a website maintenance service agreement, you can find = consulting companies at <a class=3D"external-link" = href=3D"http://plone.com/providers" target=3D"_self" title=3D"" = style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: = none; color: rgb(66, 117, 151); border-bottom-width: 1px; = border-bottom-style: solid; border-bottom-color: rgb(204, 204, = 204);">plone.com/providers </a>and <a = href=3D"https://plone.org/support/network" class=3D"external-link" = style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: = none; color: rgb(66, 117, 151); border-bottom-width: 1px; = border-bottom-style: solid; border-bottom-color: rgb(204, 204, = 204);">plone.org/support/network </a>.</p><p style=3D"margin: 0px = 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" = class=3D"">There is also <a href=3D"https://plone.org/support" = style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: = none; color: rgb(66, 117, 151); border-bottom-width: 1px; = border-bottom-style: solid; border-bottom-color: rgb(204, 204, 204);" = class=3D"">free support </a>available online via the <a = class=3D"external-link" href=3D"http://plone.org/support" target=3D"_self"= title=3D"" style=3D"margin: 0px; padding: 0px; outline: none; = text-decoration: none; color: rgb(66, 117, 151); border-bottom-width: = 1px; border-bottom-style: solid; border-bottom-color: rgb(204, 204, = 204);">Plone IRC channel</a> and the <a class=3D"external-link" = href=3D"http://community.plone.org/" target=3D"_self" title=3D"" = style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: = none; color: rgb(66, 117, 151); border-bottom-width: 1px; = border-bottom-style: solid; border-bottom-color: rgb(204, 204, = 204);">Plone community forum</a>.</p><h3 style=3D"margin: 0.5em 0px 0px; = padding: 0px; font-size: 1.125em; font-family: 'Helvetica Neue', Arial, = FreeSans, sans-serif; line-height: 22.5px; color: rgb(68, 68, 68);" = class=3D"">Thanks</h3><p style=3D"margin: 0px 0px 1em; padding: 0px; = font-size: 13px; line-height: 1.5em;" class=3D"">The Plone Security Team = is grateful to <span style=3D"margin: 0px; padding: 0px;" = class=3D"">Giovanni Monteiro Calanzani and <span style=3D"margin: = 0px; padding: 0px;" class=3D"">Glauter de Sousa = Vilela</span></span><span style=3D"margin: 0px; padding: 0px;" = class=3D"">, who reported the vulnerability.</span></p><hr = style=3D"margin: 0px; padding: 0px;" class=3D""><h2 style=3D"margin: = 0.5em 0px 0px; padding: 0px; font-size: 1.375em; font-family: 'Helvetica = Neue', Arial, FreeSans, sans-serif; line-height: 27.5px; color: rgb(68, = 68, 68); letter-spacing: -1px;" class=3D"">Questions and Answers</h2><p = style=3D"margin: 0px 0px 1em; padding: 0px; font-size: 13px; = line-height: 1.5em;" class=3D""><b style=3D"margin: 0px; padding: 0px;" = class=3D""></b><b style=3D"margin: 0px; padding: 0px;" class=3D"">Q. = What is involved in applying the patch? <br style=3D"margin: 0px; = padding: 0px;" class=3D""></b>A. Patches are made available as = tarball-style archives that may be unpacked into the =E2=80=9Cproducts=E2=80= =9D folder of a buildout installation and as Python packages that may be = installed by editing a buildout configuration file and running buildout. = Patching is generally easy and quick to accomplish.</p><p style=3D"margin:= 0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" = class=3D""><b style=3D"margin: 0px; padding: 0px;" class=3D""></b><b = style=3D"margin: 0px; padding: 0px;" class=3D"">Q: My site is highly = visible and mission-critical. I hear the patch has already been = developed. Can I get the fix before the release date? </b><br = style=3D"margin: 0px; padding: 0px;" class=3D"">A: Plone patches are = always made available to <b style=3D"margin: 0px; padding: 0px;" = class=3D"">all users at the same time</b>. There are no = exceptions.</p><p style=3D"margin: 0px 0px 1em; padding: 0px; font-size: = 13px; line-height: 1.5em;" class=3D""><b style=3D"margin: 0px; padding: = 0px;" class=3D"">General questions </b><span style=3D"margin: 0px; = padding: 0px;" class=3D""></span><b style=3D"margin: 0px; padding: 0px;" = class=3D"">about this announcement</b><span style=3D"margin: 0px; = padding: 0px;" class=3D"">, Plone patching procedures, and availability = of support may be addressed to the </span><a = href=3D"https://plone.org/support" style=3D"margin: 0px; padding: 0px; = outline: none; text-decoration: none; color: rgb(66, 117, 151); = border-bottom-width: 1px; border-bottom-style: solid; = border-bottom-color: rgb(204, 204, 204);" class=3D"">Plone support = forums </a><span style=3D"margin: 0px; padding: 0px;" class=3D"">. = If you have </span><b style=3D"margin: 0px; padding: 0px;" = class=3D"">specific questions </b><span style=3D"margin: 0px; = padding: 0px;" class=3D"">about this vulnerability or its handling, = contact the </span><a href=3D"mailto:security-z4DKO/[email protected]" = style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: = none; color: rgb(66, 117, 151); border-bottom-width: 1px; = border-bottom-style: solid; border-bottom-color: rgb(204, 204, 204);" = class=3D"">Plone Security Team </a>directly<span style=3D"margin: = 0px; padding: 0px;" class=3D"">.</span></p><p style=3D"margin: 0px 0px = 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" class=3D""><b = style=3D"margin: 0px; padding: 0px;" class=3D"">To report potentially = security-related issues</b><b style=3D"margin: 0px; padding: 0px;" = class=3D"">, </b>e-mail the Plone Security Team directly at <a = href=3D"mailto:security-z4DKO/[email protected]" style=3D"margin: 0px; padding: 0px; = outline: none; text-decoration: none; color: rgb(66, 117, 151); = border-bottom-width: 1px; border-bottom-style: solid; = border-bottom-color: rgb(204, 204, 204);" = class=3D"">security-z4DKO/[email protected]</a>. We are always happy to credit = individuals and companies who make responsible disclosures.</p><p = style=3D"margin: 0px 0px 1em; padding: 0px; font-size: 13px; = line-height: 1.5em;" class=3D"">The Plone Security Team is an = all-volunteer team. If you'd like to help the team, as a developer, a = tester, or as a financial sponsor, please email the team at <a = class=3D"email-link" = href=3D"mailto:security-z4DKO/[email protected]?subject=3Dsupport%20for%20the%20Plone%20= Security%20Team" target=3D"_self" title=3D"" style=3D"margin: 0px; = padding: 0px; outline: none; text-decoration: none; color: rgb(66, 117, = 151); border-bottom-width: 1px; border-bottom-style: solid; = border-bottom-color: rgb(204, 204, 204);">security-z4DKO/[email protected]</a>.</p><h3 = style=3D"margin: 0.5em 0px 0px; padding: 0px; font-size: 1.125em; = font-family: 'Helvetica Neue', Arial, FreeSans, sans-serif; line-height: = 22.5px; color: rgb(68, 68, 68);" class=3D"">Information for = Vulnerability Database Maintainers</h3><p style=3D"margin: 0px 0px 1em; = padding: 0px; font-size: 13px; line-height: 1.5em;" class=3D"">We have = already applied for CVE numbers for these issues. Further information on = individual vulnerabilities (including CVSS scores, CWE identifiers and = summaries) is available at <a = href=3D"https://plone.org/products/plone/security/" style=3D"margin: = 0px; padding: 0px; outline: none; text-decoration: none; color: rgb(66, = 117, 151); border-bottom-width: 1px; border-bottom-style: solid; = border-bottom-color: rgb(204, 204, 204);" class=3D"">the full = vulnerability list</a></p></div></div></div></body></html>= --Apple-Mail=_278BAFC8-5A45-4D27-9FB0-D65980DE5D0F-- --===============6506724317865230549== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline ------------------------------------------------------------------------------ --===============6506724317865230549== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Plone-Announce mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/plone-announce --===============6506724317865230549==--