Security vulnerability: 20151208 — Plone CMS: Open Source Content Management

"Announcement of Plone releases and security-related notifications. Recommended subscription for all Plone developers and site admins." <[email protected]> Tue, 8 Dec 2015 09:19:56 -0600
Newsgroups gmane.comp.web.zope.plone.announce
Message-ID <D2094A3B-E769-4A51-9704-42FF6CA9DE45__36304.6190738261$1449668754$gmane$org@plone.org>
--===============6506724317865230549==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_278BAFC8-5A45-4D27-9FB0-D65980DE5D0F"


--Apple-Mail=_278BAFC8-5A45-4D27-9FB0-D65980DE5D0F
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8


> =
https://plone.org/products/plone/security/advisories/20151208-announcement=
 =
<https://plone.org/products/plone/security/advisories/20151208-announcemen=
t>

Security vulnerability: 20151208
Patches to Plone for unauthorized disclosure of registered user =
information
Versions Affected: All current Plone versions.=20
Versions Not Affected: None.

Nature of vulnerability: Allows unauthorized disclosure of registered =
user information

The patch can be added to buildouts as Products.PloneHotfix20151208 =
(available from pypi.python.org =
<https://pypi.python.org/pypi?%3Aaction=3Dsearch&term=3DProducts.PloneHotf=
ix20151208&submit=3Dsearch>) or downloaded from Plone.org =
<https://plone.org/products/plone-hotfix/releases/20151208>
This patch is compatible with all supported Plone versions (i.e. Plone =
4, Plone 5). It may work on earlier versions of Plone, but as these are =
officially unsupported they have not undergone the same level of testing =
with the patch.

Installation
Full installation instructions are available on the HotFix release page =
<https://plone.org/products/plone-hotfix/releases/20151208>.

Extra Help
If you do not have in-house server administrators or a website =
maintenance service agreement, you can find consulting companies at =
plone.com/providers=C2=A0 <http://plone.com/providers>and =
plone.org/support/network=C2=A0 <https://plone.org/support/network>.

There is also free support=C2=A0 <https://plone.org/support>available =
online via the Plone IRC channel <http://plone.org/support> and the =
Plone community forum <http://community.plone.org/>.

Thanks
The Plone Security Team is grateful to Giovanni Monteiro Calanzani and =
Glauter de Sousa Vilela, who reported the vulnerability.

Questions and Answers
Q. What is involved in applying the patch?=20
A. Patches are made available as tarball-style archives that may be =
unpacked into the =E2=80=9Cproducts=E2=80=9D folder of a buildout =
installation and as Python packages that may be installed by editing a =
buildout configuration file and running buildout. Patching is generally =
easy and quick to accomplish.

Q: My site is highly visible and mission-critical. I hear the patch has =
already been developed. Can I get the fix before the release date?=20
A: Plone patches are always made available to all users at the same =
time. There are no exceptions.

General questions about this announcement, Plone patching procedures, =
and availability of support may be addressed to the Plone support =
forums=C2=A0 <https://plone.org/support>. If you have specific questions =
about this vulnerability or its handling, contact the Plone Security =
Team=C2=A0 <mailto:security-z4DKO/[email protected]>directly.

To report potentially security-related issues, e-mail the Plone Security =
Team directly at security-z4DKO/[email protected] <mailto:security-z4DKO/[email protected]>. We are =
always happy to credit individuals and companies who make responsible =
disclosures.

The Plone Security Team is an all-volunteer team. If you'd like to help =
the team, as a developer, a tester, or as a financial sponsor, please =
email the team at security-z4DKO/[email protected] =
<mailto:security-z4DKO/[email protected]?subject=3Dsupport%20for%20the%20Plone%20Securit=
y%20Team>.

Information for Vulnerability Database Maintainers
We have already applied for CVE numbers for these issues. Further =
information on individual vulnerabilities (including CVSS scores, CWE =
identifiers and summaries) is available at the full vulnerability list =
<https://plone.org/products/plone/security/>=

--Apple-Mail=_278BAFC8-5A45-4D27-9FB0-D65980DE5D0F
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dutf-8"><base></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D""><base class=3D""><div =
class=3D"Apple-Mail-URLShareUserContentTopClass"><br class=3D""></div><div=
 class=3D"Apple-Mail-URLShareWrapperClass" style=3D"position: relative =
!important;"><blockquote type=3D"cite" style=3D"border-left-style: none; =
color: inherit; padding: inherit; margin: inherit;" class=3D""><a =
href=3D"https://plone.org/products/plone/security/advisories/20151208-anno=
uncement" =
class=3D"">https://plone.org/products/plone/security/advisories/20151208-a=
nnouncement</a><br class=3D""></blockquote><br class=3D""></div><div =
class=3D"Apple-Mail-URLShareWrapperClass" style=3D"position: relative =
!important;"><h1 id=3D"parent-fieldname-title" =
class=3D"documentFirstHeading" style=3D"margin: 0px; padding: 0px; =
font-size: 1.625em; font-family: 'Helvetica Neue', Arial, FreeSans, =
sans-serif; line-height: 32.5px; letter-spacing: -1px;">Security =
vulnerability: 20151208</h1><div id=3D"viewlet-below-content-title" =
style=3D"margin: 0px; padding: 0px; font-family: Arial, FreeSans, =
sans-serif; font-size: 16px;" class=3D""><div class=3D"RatingViewlet" =
style=3D"margin: 0px; padding: 0px;"></div></div><div =
id=3D"parent-fieldname-description" class=3D"documentDescription" =
style=3D"margin: 0px 0px 1em; padding: 0px; color: gray !important; =
font-weight: bold !important; font-size: 1em !important; line-height: =
normal !important; font-family: 'Helvetica Neue', Arial, FreeSans, =
sans-serif !important;">Patches to Plone for unauthorized disclosure of =
registered user information</div><div id=3D"viewlet-above-content-body" =
style=3D"margin: 0px; padding: 0px; font-family: Arial, FreeSans, =
sans-serif; font-size: 16px;" class=3D""></div><div id=3D"content-core" =
style=3D"margin: 0px; padding: 0px; font-family: Arial, FreeSans, =
sans-serif; font-size: 16px;" class=3D""><div id=3D"parent-fieldname-text"=
 class=3D"plain" style=3D"margin: 0px; padding: 0px;"><p style=3D"margin: =
0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" =
class=3D""><b style=3D"margin: 0px; padding: 0px;" class=3D"">Versions =
Affected:&nbsp;</b>All current Plone versions.&nbsp;<br style=3D"margin: =
0px; padding: 0px;" class=3D""><b style=3D"margin: 0px; padding: 0px;" =
class=3D"">Versions Not Affected:&nbsp;</b>None.</p><p style=3D"margin: =
0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" =
class=3D""><strong style=3D"margin: 0px; padding: 0px;" class=3D"">Nature =
of vulnerability:</strong>&nbsp;Allows&nbsp;unauthorized disclosure of =
registered user information</p><p style=3D"margin: 0px 0px 1em; padding: =
0px; font-size: 13px; line-height: 1.5em;" class=3D"">The patch can be =
added to buildouts as Products.PloneHotfix20151208 (available =
from&nbsp;<a class=3D"external-link" =
href=3D"https://pypi.python.org/pypi?%3Aaction=3Dsearch&amp;term=3DProduct=
s.PloneHotfix20151208&amp;submit=3Dsearch" target=3D"_self" title=3D"" =
style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: =
none; color: rgb(66, 117, 151); border-bottom-width: 1px; =
border-bottom-style: solid; border-bottom-color: rgb(204, 204, =
204);">pypi.python.org</a>) or downloaded from&nbsp;<a title=3D"" =
href=3D"https://plone.org/products/plone-hotfix/releases/20151208" =
class=3D"external-link" target=3D"_self" style=3D"margin: 0px; padding: =
0px; outline: none; text-decoration: none; color: rgb(66, 117, 151); =
border-bottom-width: 1px; border-bottom-style: solid; =
border-bottom-color: rgb(204, 204, 204);">Plone.org</a></p><p =
style=3D"margin: 0px 0px 1em; padding: 0px; font-size: 13px; =
line-height: 1.5em;" class=3D"">This patch is compatible with all =
supported Plone versions (i.e. Plone 4, Plone 5). It may work on earlier =
versions of Plone, but as these are officially unsupported they have not =
undergone the same level of testing with&nbsp;the patch.</p><h3 =
style=3D"margin: 0.5em 0px 0px; padding: 0px; font-size: 1.125em; =
font-family: 'Helvetica Neue', Arial, FreeSans, sans-serif; line-height: =
22.5px; color: rgb(68, 68, 68);" class=3D"">Installation</h3><p =
style=3D"margin: 0px 0px 1em; padding: 0px; font-size: 13px; =
line-height: 1.5em;" class=3D"">Full installation instructions are =
available on&nbsp;<a title=3D"" =
href=3D"https://plone.org/products/plone-hotfix/releases/20151208" =
class=3D"external-link" target=3D"_self" style=3D"margin: 0px; padding: =
0px; outline: none; text-decoration: none; color: rgb(66, 117, 151); =
border-bottom-width: 1px; border-bottom-style: solid; =
border-bottom-color: rgb(204, 204, 204);">the HotFix release =
page</a>.</p><h3 style=3D"margin: 0.5em 0px 0px; padding: 0px; =
font-size: 1.125em; font-family: 'Helvetica Neue', Arial, FreeSans, =
sans-serif; line-height: 22.5px; color: rgb(68, 68, 68);" class=3D"">Extra=
 Help</h3><p style=3D"margin: 0px 0px 1em; padding: 0px; font-size: =
13px; line-height: 1.5em;" class=3D"">If you do not have in-house server =
administrators or a website maintenance service agreement, you can find =
consulting companies at&nbsp;<a class=3D"external-link" =
href=3D"http://plone.com/providers" target=3D"_self" title=3D"" =
style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: =
none; color: rgb(66, 117, 151); border-bottom-width: 1px; =
border-bottom-style: solid; border-bottom-color: rgb(204, 204, =
204);">plone.com/providers&nbsp;</a>and&nbsp;<a =
href=3D"https://plone.org/support/network" class=3D"external-link" =
style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: =
none; color: rgb(66, 117, 151); border-bottom-width: 1px; =
border-bottom-style: solid; border-bottom-color: rgb(204, 204, =
204);">plone.org/support/network&nbsp;</a>.</p><p style=3D"margin: 0px =
0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" =
class=3D"">There is also&nbsp;<a href=3D"https://plone.org/support" =
style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: =
none; color: rgb(66, 117, 151); border-bottom-width: 1px; =
border-bottom-style: solid; border-bottom-color: rgb(204, 204, 204);" =
class=3D"">free support&nbsp;</a>available online via the&nbsp;<a =
class=3D"external-link" href=3D"http://plone.org/support" target=3D"_self"=
 title=3D"" style=3D"margin: 0px; padding: 0px; outline: none; =
text-decoration: none; color: rgb(66, 117, 151); border-bottom-width: =
1px; border-bottom-style: solid; border-bottom-color: rgb(204, 204, =
204);">Plone IRC channel</a>&nbsp;and the&nbsp;<a class=3D"external-link" =
href=3D"http://community.plone.org/" target=3D"_self" title=3D"" =
style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: =
none; color: rgb(66, 117, 151); border-bottom-width: 1px; =
border-bottom-style: solid; border-bottom-color: rgb(204, 204, =
204);">Plone community forum</a>.</p><h3 style=3D"margin: 0.5em 0px 0px; =
padding: 0px; font-size: 1.125em; font-family: 'Helvetica Neue', Arial, =
FreeSans, sans-serif; line-height: 22.5px; color: rgb(68, 68, 68);" =
class=3D"">Thanks</h3><p style=3D"margin: 0px 0px 1em; padding: 0px; =
font-size: 13px; line-height: 1.5em;" class=3D"">The Plone Security Team =
is grateful to&nbsp;<span style=3D"margin: 0px; padding: 0px;" =
class=3D"">Giovanni Monteiro Calanzani and&nbsp;<span style=3D"margin: =
0px; padding: 0px;" class=3D"">Glauter de Sousa =
Vilela</span></span><span style=3D"margin: 0px; padding: 0px;" =
class=3D"">, who reported the vulnerability.</span></p><hr =
style=3D"margin: 0px; padding: 0px;" class=3D""><h2 style=3D"margin: =
0.5em 0px 0px; padding: 0px; font-size: 1.375em; font-family: 'Helvetica =
Neue', Arial, FreeSans, sans-serif; line-height: 27.5px; color: rgb(68, =
68, 68); letter-spacing: -1px;" class=3D"">Questions and Answers</h2><p =
style=3D"margin: 0px 0px 1em; padding: 0px; font-size: 13px; =
line-height: 1.5em;" class=3D""><b style=3D"margin: 0px; padding: 0px;" =
class=3D""></b><b style=3D"margin: 0px; padding: 0px;" class=3D"">Q. =
What is involved in applying the patch?&nbsp;<br style=3D"margin: 0px; =
padding: 0px;" class=3D""></b>A. Patches are made available as =
tarball-style archives that may be unpacked into the =E2=80=9Cproducts=E2=80=
=9D folder of a buildout installation and as Python packages that may be =
installed by editing a buildout configuration file and running buildout. =
Patching is generally easy and quick to accomplish.</p><p style=3D"margin:=
 0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" =
class=3D""><b style=3D"margin: 0px; padding: 0px;" class=3D""></b><b =
style=3D"margin: 0px; padding: 0px;" class=3D"">Q: My site is highly =
visible and mission-critical. I hear the patch has already been =
developed. Can I get the fix before the release date?&nbsp;</b><br =
style=3D"margin: 0px; padding: 0px;" class=3D"">A: Plone patches are =
always made available to&nbsp;<b style=3D"margin: 0px; padding: 0px;" =
class=3D"">all users at the same time</b>. There are no =
exceptions.</p><p style=3D"margin: 0px 0px 1em; padding: 0px; font-size: =
13px; line-height: 1.5em;" class=3D""><b style=3D"margin: 0px; padding: =
0px;" class=3D"">General questions&nbsp;</b><span style=3D"margin: 0px; =
padding: 0px;" class=3D""></span><b style=3D"margin: 0px; padding: 0px;" =
class=3D"">about this announcement</b><span style=3D"margin: 0px; =
padding: 0px;" class=3D"">, Plone patching procedures, and availability =
of support may be addressed to the&nbsp;</span><a =
href=3D"https://plone.org/support" style=3D"margin: 0px; padding: 0px; =
outline: none; text-decoration: none; color: rgb(66, 117, 151); =
border-bottom-width: 1px; border-bottom-style: solid; =
border-bottom-color: rgb(204, 204, 204);" class=3D"">Plone support =
forums&nbsp;</a><span style=3D"margin: 0px; padding: 0px;" class=3D"">. =
If you have&nbsp;</span><b style=3D"margin: 0px; padding: 0px;" =
class=3D"">specific questions&nbsp;</b><span style=3D"margin: 0px; =
padding: 0px;" class=3D"">about this vulnerability or its handling, =
contact the&nbsp;</span><a href=3D"mailto:security-z4DKO/[email protected]" =
style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: =
none; color: rgb(66, 117, 151); border-bottom-width: 1px; =
border-bottom-style: solid; border-bottom-color: rgb(204, 204, 204);" =
class=3D"">Plone Security Team&nbsp;</a>directly<span style=3D"margin: =
0px; padding: 0px;" class=3D"">.</span></p><p style=3D"margin: 0px 0px =
1em; padding: 0px; font-size: 13px; line-height: 1.5em;" class=3D""><b =
style=3D"margin: 0px; padding: 0px;" class=3D"">To report potentially =
security-related issues</b><b style=3D"margin: 0px; padding: 0px;" =
class=3D"">,&nbsp;</b>e-mail the Plone Security Team directly at&nbsp;<a =
href=3D"mailto:security-z4DKO/[email protected]" style=3D"margin: 0px; padding: 0px; =
outline: none; text-decoration: none; color: rgb(66, 117, 151); =
border-bottom-width: 1px; border-bottom-style: solid; =
border-bottom-color: rgb(204, 204, 204);" =
class=3D"">security-z4DKO/[email protected]</a>. We are always happy to credit =
individuals and companies who make responsible disclosures.</p><p =
style=3D"margin: 0px 0px 1em; padding: 0px; font-size: 13px; =
line-height: 1.5em;" class=3D"">The Plone Security Team is an =
all-volunteer team. If you'd like to help the team, as a developer, a =
tester, or as a financial sponsor, please email the team at&nbsp;<a =
class=3D"email-link" =
href=3D"mailto:security-z4DKO/[email protected]?subject=3Dsupport%20for%20the%20Plone%20=
Security%20Team" target=3D"_self" title=3D"" style=3D"margin: 0px; =
padding: 0px; outline: none; text-decoration: none; color: rgb(66, 117, =
151); border-bottom-width: 1px; border-bottom-style: solid; =
border-bottom-color: rgb(204, 204, 204);">security-z4DKO/[email protected]</a>.</p><h3 =
style=3D"margin: 0.5em 0px 0px; padding: 0px; font-size: 1.125em; =
font-family: 'Helvetica Neue', Arial, FreeSans, sans-serif; line-height: =
22.5px; color: rgb(68, 68, 68);" class=3D"">Information for =
Vulnerability Database Maintainers</h3><p style=3D"margin: 0px 0px 1em; =
padding: 0px; font-size: 13px; line-height: 1.5em;" class=3D"">We have =
already applied for CVE numbers for these issues. Further information on =
individual vulnerabilities (including CVSS scores, CWE identifiers and =
summaries) is available at&nbsp;<a =
href=3D"https://plone.org/products/plone/security/" style=3D"margin: =
0px; padding: 0px; outline: none; text-decoration: none; color: rgb(66, =
117, 151); border-bottom-width: 1px; border-bottom-style: solid; =
border-bottom-color: rgb(204, 204, 204);" class=3D"">the full =
vulnerability list</a></p></div></div></div></body></html>=

--Apple-Mail=_278BAFC8-5A45-4D27-9FB0-D65980DE5D0F--


--===============6506724317865230549==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------

--===============6506724317865230549==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Plone-Announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-announce

--===============6506724317865230549==--