Security vulnerability pre-announcemen t: 20160419 — Plone CMS

"Announcement of Plone releases and security-related notifications. Recommended subscription for all Plone developers and site admins." <[email protected]> Mon, 11 Apr 2016 10:54:57 -0500
Newsgroups gmane.comp.web.zope.plone.announce
Message-ID <[email protected]>
--===============4338845353882726207==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_BBCD4241-980D-45EB-8627-71786CBFF4BB"


--Apple-Mail=_BBCD4241-980D-45EB-8627-71786CBFF4BB
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8


> =
https://plone.org/products/plone/security/advisories/20160419-preannounce =
<https://plone.org/products/plone/security/advisories/20160419-preannounce=
>
>=20
> Security vulnerability pre-announcement: 20160419
>=20
> CVE numbers not yet issued.
>=20
> Versions Affected: All supported Plone versions (4.x, 5.x). Previous =
versions could be affected but have not been tested.
>=20
> Versions Not Affected: None.
>=20
> Nature of vulnerability: the patch will address escalated privilege =
vulnerability issues.
>=20
> The patch will be released at 2016-04-19 15:00 UTC =
<http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2016&mo=3D4&d=
=3D19&h=3D15&mn=3D0>.
>=20
> Preparation
>=20
> This is a pre-announcement of availability of this security fix.=20
>=20
> Standard security advice
>=20
> Make sure that the Zope/Plone service is running with minimum =
privileges. Ideally, the Zope and ZEO services should be able to write =
only to log and data directories. Plone sites installed through our =
installers already do this.
> Use an intrusion detection system that monitors key system resources =
for unauthorized changes.
> Monitor your Zope, reverse-proxy request and system logs for unusual =
activity.
> Make sure your administrator stays up to date, by following the =
special low-volume Plone Security Announcements list via email =
<https://lists.sourceforge.net/lists/listinfo/plone-announce>, RSS =
<https://plone.org/products/plone/security/advisories/all-advisories/RSS> =
and/or Twitter <https://twitter.com/plone>
> These are standard precautions that should be employed on any =
production system, and are not tied to this fix.
>=20
> Extra Help
>=20
> Should you not have in-house server administrators or a service =
agreement for supporting your website, you can find consulting companies =
at plone.com/providers=C2=A0 <http://plone.com/providers>and =
plone.org/support/network <https://plone.org/support/network>
> There is also free support=C2=A0 <https://plone.org/support>available =
online via Plone mailing lists and the Plone IRC channels.
>=20
> Q: When will the patch be made available?
> A: The Plone Security Team will release the patch at 2016-04-19 15:00 =
UTC =
<http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2016&mo=3D4&d=
=3D19&h=3D15&mn=3D0>.
>=20
> Q. What will be involved in applying the patch?
> A. Patches are made available as tarball-style archives that may be =
unpacked into the products folder of a buildout installation and as =
Python packages that may be installed by editing a buildout =
configuration file and running buildout. Patching is generally easy and =
quick to accomplish.
>=20
> Q: How were these vulnerabilities found?
> A: The vulnerabilities were found by users submitting them to the =
security mailing list.
>=20
> Q: My site is highly visible and mission-critical. I hear the patch =
has already been developed. Can I get the fix before the release date?
> A: No. The patch will be made available to all administrators at the =
same time. There are no exceptions.
>=20
> Q: If the patch has been developed already, why isn't it made =
available to the public now?
> A: The Security Team is still testing the patch against a wide variety =
of configurations and running various scenarios thoroughly. The team is =
also making sure everybody has appropriate time to plan to patch their =
Plone installation(s). Some consultancy organizations have hundreds of =
sites to patch and need the extra time to coordinate their efforts with =
their clients.
>=20
> Q: How does one exploit the vulnerability?
> A: This information will not be made public until after the patch is =
made available.
>=20
> Q: Is my Plone site at risk for this vulnerability? How do I know if =
my site has been exploited? How can I confirm that the hotfix is =
installed correctly and my site is protected?
>=20
> A: Details about the vulnerability will be revealed at the same time =
as the patch.
>=20
> Q: How can I report other potential security vulnerabilities?
>=20
> A: Please email the Plone Security Team at security-z4DKO/[email protected] =
<mailto:security-z4DKO/[email protected]> rather than publicly discussing potential =
security issues.
>=20
> Q: How can I apply the patch without affecting my users?
>=20
> A: Even though this patch does NOT require you to run buildout, you =
can run buildout without affecting your users. You can restart a =
multi-client Plone install without affecting your users; see =
http://docs.plone.org/manage/deploying/processes.html =
<http://docs.plone.org/manage/deploying/processes.html> =20
>=20
> Q: How do I get help patching my site?
>=20
> A: Plone service providers are listed at plone.com/providers=C2=A0 =
<http://plone.com/providers>and plone.org/support/network =
<https://plone.org/support/network> There is also free support=C2=A0 =
<https://plone.org/support>available online via Plone mailing lists and =
the Plone IRC channels
>=20
> Q: Who is on the Plone Security Team and how is it funded?
>=20
> A: The Plone Security Team is made up of volunteers who are =
experienced developers familiar with the Plone code base and with =
security exploits. The Plone Security Team is not funded; members and/or =
their employers have volunteered their time in the interests of the =
greater Plone community.
>=20
> Q: How can I help the Plone Security Team?
>=20
> A: The Plone Security Team is looking for help from security-minded =
developers and testers. Volunteers must be known to the Security Team =
and have been part of the Plone community for some time. To help the =
Security Team financially, your donations are most welcome at =
http://plone.org/donate <http://plone.org/donate>.
>=20
> General questions about this announcement, Plone patching procedures, =
and availability of support may be addressed to the Plone support forums =
<https://plone.org/support> If you have specific questions about this =
vulnerability or its handling, contact the Plone Security Team at =
security-z4DKO/[email protected] <mailto:security-z4DKO/[email protected]>
> To report potentially security-related issues, email the Plone =
Security Team at security-z4DKO/[email protected] <mailto:security-z4DKO/[email protected]> We are =
always happy to credit individuals and companies who make responsible =
disclosures.
>=20
> Information for Vulnerability Database Maintainers
>=20
> We will apply for CVE numbers for these issues. Further information on =
individual vulnerabilities (including CVSS scores, CWE identifiers and =
summaries) will be available at the full vulnerability list. =
<https://plone.org/hotfixes>=

--Apple-Mail=_BBCD4241-980D-45EB-8627-71786CBFF4BB
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dus-ascii"><base></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D""><base class=3D""><div =
class=3D"Apple-Mail-URLShareUserContentTopClass"><br class=3D""></div><div=
 class=3D"Apple-Mail-URLShareWrapperClass" style=3D"position: relative =
!important;"><blockquote type=3D"cite" style=3D"border-left-style: none; =
color: inherit; padding: inherit; margin: inherit;" class=3D""><div =
class=3D""><div class=3D"original-url"><a =
href=3D"https://plone.org/products/plone/security/advisories/20160419-prea=
nnounce" =
class=3D"">https://plone.org/products/plone/security/advisories/20160419-p=
reannounce</a><br class=3D""><br class=3D""></div><div id=3D"article" =
role=3D"article" style=3D"-webkit-locale: en; border-bottom-width: 0px;" =
class=3D"">
        <!-- This node will contain a number of div.page. -->
    <div class=3D"page"><h1 class=3D"title">Security vulnerability =
pre-announcement: 20160419</h1><p class=3D"">CVE numbers not yet =
issued.</p><p class=3D""><strong class=3D"">Versions Affected:</strong> =
All supported Plone versions (4.x, 5.x). Previous versions could be =
affected but have not been tested.</p><p class=3D""><strong =
class=3D"">Versions Not Affected:</strong> None.</p><p class=3D""><strong =
class=3D"">Nature of vulnerability:</strong>&nbsp;the patch will address =
escalated privilege vulnerability issues.</p><p class=3D""><strong =
class=3D"">The patch will be released at <a =
href=3D"http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2016&a=
mp;mo=3D4&amp;d=3D19&amp;h=3D15&amp;mn=3D0" target=3D"_blank" title=3D"" =
class=3D"">2016-04-19 15:00 UTC</a>.</strong></p>
<h2 class=3D"">Preparation</h2><p class=3D"">This is a pre-announcement =
of availability of this security fix.&nbsp;</p>
<h3 class=3D"">Standard security advice</h3>
<ul class=3D""><li class=3D"">Make sure that the Zope/Plone service is =
running with minimum privileges. Ideally, the Zope and ZEO services =
should be able to write only to log and data directories. Plone sites =
installed through our installers already do this.</li>
<li class=3D"">Use an intrusion detection system that monitors key =
system resources for unauthorized changes.</li>
<li class=3D"">Monitor your Zope, reverse-proxy request and system logs =
for unusual activity.</li>
<li class=3D"">Make sure your administrator stays up to date, by =
following the special low-volume <a =
href=3D"https://lists.sourceforge.net/lists/listinfo/plone-announce" =
target=3D"_self" title=3D"" class=3D"">Plone Security Announcements list =
via email</a>, <a =
href=3D"https://plone.org/products/plone/security/advisories/all-advisorie=
s/RSS" class=3D"">RSS</a> and/or <a href=3D"https://twitter.com/plone" =
target=3D"_self" title=3D"" class=3D"">Twitter</a></li>
</ul><p class=3D"">These are standard precautions that should be =
employed on any production system, and are not tied to this fix.</p>
<h3 class=3D"">Extra Help</h3><p class=3D"">Should you not have in-house =
server administrators or a service agreement for supporting your =
website, you can find consulting companies at&nbsp;<a =
href=3D"http://plone.com/providers" =
class=3D"">plone.com/providers&nbsp;</a>and&nbsp;<a =
href=3D"https://plone.org/support/network" =
class=3D"">plone.org/support/network</a></p><p class=3D"">There is =
also&nbsp;<a href=3D"https://plone.org/support" class=3D"">free =
support&nbsp;</a>available online via Plone mailing lists and the Plone =
IRC channels.</p><p class=3D""><strong class=3D"">Q: When will the patch =
be made available?<br class=3D""></strong>A: The Plone Security Team =
will release the patch at <a =
href=3D"http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2016&a=
mp;mo=3D4&amp;d=3D19&amp;h=3D15&amp;mn=3D0" target=3D"_blank" title=3D"" =
class=3D"">2016-04-19 15:00 UTC</a>.</p><p class=3D""><strong =
class=3D"">Q. What will be involved in applying the patch?<br =
class=3D""></strong>A. Patches are made available as tarball-style =
archives that may be unpacked into the <kbd class=3D"">products</kbd> =
folder of a buildout installation and as Python packages that may be =
installed by editing a buildout configuration file and running buildout. =
Patching is generally easy and quick to accomplish.</p><p =
class=3D""><strong class=3D"">Q: How were these vulnerabilities =
found?<br class=3D""></strong>A: The vulnerabilities were found by users =
submitting them to the security mailing list.</p><p class=3D""><strong =
class=3D"">Q: My site is highly visible and mission-critical. I hear the =
patch has already been developed. Can I get the fix before the release =
date?</strong><br class=3D""> A: No. The patch will be made available to =
<strong class=3D"">all administrators at the same time</strong>. There =
are no exceptions.</p><p class=3D""><strong class=3D"">Q: If the patch =
has been developed already, why isn't it made available to the public =
now?<br class=3D""></strong> A: The Security Team is still testing the =
patch against a wide variety of configurations and running various =
scenarios thoroughly. The team is also making sure everybody has =
appropriate time to plan to patch their Plone installation(s). Some =
consultancy organizations have hundreds of sites to patch and need the =
extra time to coordinate their efforts with their clients.</p><p =
class=3D""><strong class=3D"">Q: How does one exploit the =
vulnerability?<br class=3D""></strong>A: This information will not be =
made public until after the patch is made available.</p><p =
class=3D""><strong class=3D"">Q: Is my Plone site at risk for this =
vulnerability?</strong><strong class=3D"">&nbsp;How do I know if my site =
has been exploited?</strong><strong class=3D"">&nbsp;How can I confirm =
that the hotfix is installed correctly and my site is =
protected?</strong></p><p class=3D"">A: Details about the vulnerability =
will be revealed at the same time as the patch.</p><p class=3D""><strong =
class=3D"">Q: How can I report other potential security =
vulnerabilities?</strong></p><p class=3D"">A: Please email the Plone =
Security Team at&nbsp;<a href=3D"mailto:security-z4DKO/[email protected]" =
class=3D"">security-z4DKO/[email protected]</a>&nbsp;rather than publicly discussing =
potential security issues.</p><p class=3D""><strong class=3D"">Q: How =
can I apply the patch without affecting my users?</strong></p><p =
class=3D"">A: Even though this patch does NOT require you to run =
buildout, you can run buildout without affecting your users. You can =
restart a multi-client Plone install without affecting your users; =
see&nbsp;<a href=3D"http://docs.plone.org/manage/deploying/processes.html"=
 =
class=3D"">http://docs.plone.org/manage/deploying/processes.html</a>&nbsp;=
&nbsp;</p><p class=3D""><strong class=3D"">Q: How do I get help patching =
my site?</strong></p><p class=3D"">A: Plone service providers are listed =
at&nbsp;<a href=3D"http://plone.com/providers" =
class=3D"">plone.com/providers&nbsp;</a>and&nbsp;<a =
href=3D"https://plone.org/support/network" =
class=3D"">plone.org/support/network</a>&nbsp;There is also&nbsp;<a =
href=3D"https://plone.org/support" class=3D"">free =
support&nbsp;</a>available online via Plone mailing lists and the Plone =
IRC channels</p><p class=3D""><strong class=3D"">Q: Who is on the Plone =
Security Team and how is it funded?</strong></p><p class=3D"">A: The =
Plone Security Team is made up of volunteers who are experienced =
developers familiar with the Plone code base and with security exploits. =
The Plone Security Team is not funded; members and/or their employers =
have volunteered their time in the interests of the greater Plone =
community.</p><p class=3D""><strong class=3D"">Q: How can I help the =
Plone Security Team?</strong></p><p class=3D"">A: The Plone Security =
Team is looking for help from&nbsp;security-minded developers and =
testers. Volunteers must be known to the Security Team and have been =
part of the Plone community for some time. To help the Security Team =
financially, your donations are most welcome at <a =
href=3D"http://plone.org/donate" target=3D"_blank" title=3D"" =
class=3D"">http://plone.org/donate</a>.</p><p class=3D""><strong =
class=3D"">General questions about this announcement</strong>, Plone =
patching procedures, and availability of support may be addressed to =
the&nbsp;<a href=3D"https://plone.org/support" class=3D"">Plone support =
forums</a>&nbsp;If you have&nbsp;specific questions&nbsp;about this =
vulnerability or its handling, contact the&nbsp;Plone Security Team =
at&nbsp;<a href=3D"mailto:security-z4DKO/[email protected]" =
class=3D"">security-z4DKO/[email protected]</a></p><p class=3D""><strong class=3D"">To =
report potentially security-related issues</strong>,&nbsp;email the =
Plone Security Team at&nbsp;<a href=3D"mailto:security-z4DKO/[email protected]" =
class=3D"">security-z4DKO/[email protected]</a>&nbsp;We are always happy to credit =
individuals and companies who make responsible disclosures.</p>
<h3 class=3D"">Information for Vulnerability Database Maintainers</h3><p =
class=3D"">We will apply for CVE numbers for these issues. Further =
information on individual vulnerabilities (including CVSS scores, CWE =
identifiers and summaries) will be available at&nbsp;<a =
href=3D"https://plone.org/hotfixes" class=3D"">the full vulnerability =
list.</a></p></div></div></div></blockquote></div></body></html>=

--Apple-Mail=_BBCD4241-980D-45EB-8627-71786CBFF4BB--


--===============4338845353882726207==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
--===============4338845353882726207==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Plone-Announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-announce

--===============4338845353882726207==--