Security patch released: 20160419 — Plone CMS
"Announcement of Plone releases and security-related notifications. Recommended subscription for all Plone developers and site admins." <[email protected]> Tue, 19 Apr 2016 10:00:36 -0500
| Newsgroups | gmane.comp.web.zope.plone.announce |
|---|---|
| Message-ID | <[email protected]> |
--===============0109656175395882493== Content-Type: multipart/alternative; boundary="Apple-Mail=_D34801DC-12F5-4756-A831-6CC09A15C261" --Apple-Mail=_D34801DC-12F5-4756-A831-6CC09A15C261 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 > = https://plone.org/products/plone/security/advisories/20160419-announcement= = <https://plone.org/products/plone/security/advisories/20160419-announcemen= t> >=20 > Security patch released: 20160419 >=20 > CVE numbers not yet issued. >=20 > Versions Affected: All supported Plone versions (4.x, 5.x). Previous = versions could be affected but have not been tested. >=20 > Versions Not Affected: None. >=20 > Nature of vulnerability: Patches multiple attack vectors. >=20 > The patch can be added to buildouts as Products.PloneHotfix20160419 = (available from pypi.python.org = <https://pypi.python.org/pypi/Products.PloneHotfix20160419>) or = downloaded from Plone.org = <https://plone.org/products/plone-hotfix/releases/20160419> > This patch is compatible with all supported Plone versions (i.e. Plone = 4, Plone 5). It may work on earlier versions of Plone, but as these are = officially unsupported they have not undergone the same level of testing = with the patch. >=20 > Installation >=20 > Full installation instructions are available on the HotFix release = page <https://plone.org/security/20160419>. >=20 > Extra Help >=20 > If you do not have in-house server administrators or a website = maintenance service agreement, you can find consulting companies at = plone.com/providers <http://plone.com/providers>and = plone.org/support/network <https://plone.org/support/network>. >=20 > There is also free support <https://plone.org/support>available = online via the Plone IRC channel <http://plone.org/support> and the = Plone community forum <http://community.plone.org/>. >=20 > Thanks >=20 > The Plone Security Team is grateful to Giovanni Monteiro Calanzani and = Glauter de Sousa Vilela, who reported the vulnerability. >=20 > Questions and Answers >=20 > What is involved in applying the patch?=20 > Patches are made available as tarball-style archives that may be = unpacked into the =E2=80=9Cproducts=E2=80=9D folder of a buildout = installation and as Python packages that may be installed by editing a = buildout configuration file and running buildout. Patching is generally = easy and quick to accomplish. >=20 > How were these vulnerabilities found? > The vulnerabilities were found by users submitting them to the = security mailing list. >=20 > My site is highly visible and mission-critical. I hear the patch has = already been developed. Can I get the fix before the release date?=20 > Plone patches are always made available to all users at the same time. = There are no exceptions. >=20 > How can I report other potential security vulnerabilities?=20 > Please email the Plone Security Team at security-z4DKO/[email protected] = <mailto:security-z4DKO/[email protected]> rather than publicly discussing potential = security issues. >=20 > How can I apply the patch without affecting my users?=20 > Even though this patch does NOT require you to run buildout, you can = run buildout without affecting your users. You can restart a = multi-client Plone install without affecting your users; see = http://docs.plone.org/manage/deploying/processes.html = <http://docs.plone.org/manage/deploying/processes.html> =20 >=20 > How do I get help patching my site?=20 > Plone service providers are listed at plone.com/providers=C2=A0 = <http://plone.com/providers>and plone.org/support/network = <https://plone.org/support/network> There is also free support=C2=A0 = <https://plone.org/support>available online via the Plone IRC channel = <http://plone.org/support> and the Plone community forum = <http://community.plone.org/>. >=20 > Who is on the Plone Security Team and how is it funded? > The Plone Security Team is made up of volunteers who are experienced = developers familiar with the Plone code base and with security exploits. = The Plone Security Team is not funded; members and/or their employers = have volunteered their time in the interests of the greater Plone = community. >=20 > How can I help the Plone Security Team?=20 > The Plone Security Team is looking for help from security-minded = developers and testers. Volunteers must be known to the Security Team = and have been part of the Plone community for some time. To help the = Security Team financially, your donations are most welcome at = http://plone.org/donate <http://plone.org/donate>. >=20 > General questions about this announcement, Plone patching procedures, = and availability of support may be addressed to the Plone support forums = <https://plone.org/support>. If you have specific questions about this = vulnerability or its handling, contact the Plone Security Team = <mailto:security-z4DKO/[email protected]>directly. >=20 > To report potentially security-related issues, e-mail the Plone = Security Team directly at security-z4DKO/[email protected] <mailto:security-z4DKO/[email protected]> = rather than publicly discussing potential security issues. We are always = happy to credit individuals and companies who make responsible = disclosures. >=20 > The Plone Security Team is an all-volunteer team. If you'd like to = help the team, as a developer, a tester, or as a financial sponsor, = please email the team at security-z4DKO/[email protected] = <mailto:security-z4DKO/[email protected]?subject=3Dsupport%20for%20the%20Plone%20Securit= y%20Team> and become a sponsor at plone.org/donate = <http://plone.org/donate> > Information for Vulnerability Database Maintainers >=20 > We have already applied for CVE numbers for these issues. Further = information on individual vulnerabilities (including CVSS scores, CWE = identifiers and summaries) is available at the full vulnerability list=C2=A0= <https://plone.org/products/plone/security/>= --Apple-Mail=_D34801DC-12F5-4756-A831-6CC09A15C261 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 <html><head><meta http-equiv=3D"Content-Type" content=3D"text/html = charset=3Dutf-8"><base></head><body style=3D"word-wrap: break-word; = -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" = class=3D""><base class=3D""><div = class=3D"Apple-Mail-URLShareUserContentTopClass"><br class=3D""></div><div= class=3D"Apple-Mail-URLShareWrapperClass" style=3D"position: relative = !important;"><blockquote type=3D"cite" style=3D"border-left-style: none; = color: inherit; padding: inherit; margin: inherit;" class=3D""><div = class=3D""><div class=3D"original-url"><a = href=3D"https://plone.org/products/plone/security/advisories/20160419-anno= uncement" = class=3D"">https://plone.org/products/plone/security/advisories/20160419-a= nnouncement</a><br class=3D""><br class=3D""></div><div id=3D"article" = role=3D"article" style=3D"-webkit-locale: en; border-bottom-width: 0px;" = class=3D""> <!-- This node will contain a number of div.page. --> <div class=3D"page"><h1 class=3D"title">Security patch released: = 20160419</h1><p class=3D"">CVE numbers not yet issued.</p><p class=3D""><b= class=3D"">Versions Affected: </b>All supported Plone versions (4.x, = 5.x). Previous versions could be affected but have not been = tested.</p><p class=3D""><b class=3D"">Versions Not Affected: </b> = None.</p><p class=3D""><strong class=3D"">Nature of = vulnerability:</strong> Patches multiple attack vectors.</p><p = class=3D"">The patch can be added to buildouts as = Products.PloneHotfix20160419 (available from <a = href=3D"https://pypi.python.org/pypi/Products.PloneHotfix20160419" = target=3D"_blank" title=3D"" class=3D"">pypi.python.org</a>) or = downloaded from <a title=3D"" = href=3D"https://plone.org/products/plone-hotfix/releases/20160419" = target=3D"_self" class=3D"">Plone.org</a></p><p class=3D"">This patch is = compatible with all supported Plone versions (i.e. Plone 4, Plone 5). It = may work on earlier versions of Plone, but as these are officially = unsupported they have not undergone the same level of testing = with the patch.</p> <h3 class=3D"">Installation</h3><p class=3D"">Full installation = instructions are available on <a title=3D"" = href=3D"https://plone.org/security/20160419" target=3D"_self" = class=3D"">the HotFix release page</a>.</p> <h3 class=3D"">Extra Help</h3><p class=3D"">If you do not have in-house = server administrators or a website maintenance service agreement, you = can find consulting companies at <a href=3D"http://plone.com/providers" = target=3D"_self" title=3D"" class=3D"">plone.com/providers </a> and <a = href=3D"https://plone.org/support/network" = class=3D"">plone.org/support/network </a>.</p><p class=3D"">There is = also <a href=3D"https://plone.org/support" class=3D"">free support </a> = available online via the <a href=3D"http://plone.org/support" = target=3D"_self" title=3D"" class=3D"">Plone IRC channel</a> and = the <a href=3D"http://community.plone.org" target=3D"_self" title=3D"" = class=3D"">Plone community forum</a>.</p> <h3 class=3D"">Thanks</h3><p class=3D"">The Plone Security Team is = grateful to Giovanni Monteiro Calanzani and Glauter de Sousa = Vilela, who reported the vulnerability.</p> <hr class=3D""><h2 class=3D"">Questions and Answers</h2><p class=3D""><b = class=3D"">What is involved in applying the patch? <br = class=3D""></b>Patches are made available as tarball-style archives that = may be unpacked into the =E2=80=9Cproducts=E2=80=9D folder of a buildout = installation and as Python packages that may be installed by editing a = buildout configuration file and running buildout. Patching is generally = easy and quick to accomplish.</p><p class=3D""><strong class=3D"">How = were these vulnerabilities found?<br class=3D""></strong>The = vulnerabilities were found by users submitting them to the security = mailing list.</p><p class=3D""><b class=3D"">My site is highly visible = and mission-critical. I hear the patch has already been developed. Can I = get the fix before the release date? </b> <br class=3D"">Plone patches = are always made available to <b class=3D"">all users at the same = time</b>. There are no exceptions.</p><p class=3D""><strong class=3D"">How= can I report other potential security vulnerabilities?</strong> <br = class=3D"">Please email the Plone Security Team at <a = href=3D"mailto:security-z4DKO/[email protected]" = class=3D"">security-z4DKO/[email protected]</a> rather than publicly discussing = potential security issues.</p><p class=3D""><strong class=3D"">How can I = apply the patch without affecting my users?</strong> <br class=3D"">Even = though this patch does NOT require you to run buildout, you can run = buildout without affecting your users. You can restart a multi-client = Plone install without affecting your users; see <a = href=3D"http://docs.plone.org/manage/deploying/processes.html" = class=3D"">http://docs.plone.org/manage/deploying/processes.html</a> = </p><p class=3D""><strong class=3D"">How do I get help patching my = site?</strong> <br class=3D"">Plone service providers are listed = at <a href=3D"http://plone.com/providers" = class=3D"">plone.com/providers </a>and <a = href=3D"https://plone.org/support/network" = class=3D"">plone.org/support/network</a> There is also <a = href=3D"https://plone.org/support" class=3D"">free = support </a>available online via the <a = href=3D"http://plone.org/support" target=3D"_self" title=3D"" = class=3D"">Plone IRC channel</a> and the <a = href=3D"http://community.plone.org" target=3D"_self" title=3D"" = class=3D"">Plone community forum</a>.</p><p class=3D""><strong = class=3D"">Who is on the Plone Security Team and how is it = funded?</strong><br class=3D""> The Plone Security Team is made up of = volunteers who are experienced developers familiar with the Plone code = base and with security exploits. The Plone Security Team is not funded; = members and/or their employers have volunteered their time in the = interests of the greater Plone community.</p><p class=3D""><strong = class=3D"">How can I help the Plone Security Team?</strong> <br = class=3D"">The Plone Security Team is looking for help = from security-minded developers and testers. Volunteers must be = known to the Security Team and have been part of the Plone community for = some time. To help the Security Team financially, your donations are = most welcome at <a href=3D"http://plone.org/donate" target=3D"_blank"= title=3D"" class=3D"">http://plone.org/donate</a>.</p><p class=3D""><b = class=3D"">General questions </b> <b class=3D""> about this = announcement</b>, Plone patching procedures, and availability of support = may be addressed to the <a href=3D"https://plone.org/support" = class=3D"">Plone support forums </a>. If you have <b class=3D"">specific = questions </b> about this vulnerability or its handling, contact the <a = href=3D"mailto:security-z4DKO/[email protected]" class=3D"">Plone Security Team = </a>directly.</p><p class=3D""><b class=3D"">To report potentially = security-related issues</b><b class=3D"">, </b> e-mail the Plone = Security Team directly at <a href=3D"mailto:security-z4DKO/[email protected]" = class=3D"">security-z4DKO/[email protected]</a> rather than publicly discussing = potential security issues. We are always happy to credit = individuals and companies who make responsible disclosures.</p><p = class=3D"">The Plone Security Team is an all-volunteer team. If you'd = like to help the team, as a developer, a tester, or as a financial = sponsor, please email the team at <a = href=3D"mailto:security-z4DKO/[email protected]?subject=3Dsupport for the Plone = Security Team" target=3D"_self" title=3D"" = class=3D"">security-z4DKO/[email protected]</a> and become a sponsor at <a = href=3D"http://plone.org/donate" target=3D"_blank" title=3D"" = class=3D"">plone.org/donate</a></p> <h3 class=3D"">Information for Vulnerability Database Maintainers</h3><p = class=3D"">We have already applied for CVE numbers for these issues. = Further information on individual vulnerabilities (including CVSS = scores, CWE identifiers and summaries) is available at <a = href=3D"https://plone.org/products/plone/security/" class=3D"">the full = vulnerability = list </a></p></div></div></div></blockquote></div></body></html>= --Apple-Mail=_D34801DC-12F5-4756-A831-6CC09A15C261-- --===============0109656175395882493== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline ------------------------------------------------------------------------------ Find and fix application performance issues faster with Applications Manager Applications Manager provides deep performance insights into multiple tiers of your business applications. It resolves application problems quickly and reduces your MTTR. Get your free trial! https://ad.doubleclick.net/ddm/clk/302982198;130105516;z --===============0109656175395882493== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Plone-Announce mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/plone-announce --===============0109656175395882493==--