Security patch released: 20160830 — Site

"Announcement of Plone releases and security-related notifications. Recommended subscription for all Plone developers and site admins." <[email protected]> Tue, 30 Aug 2016 10:08:49 -0500
Newsgroups gmane.comp.web.zope.plone.announce
Message-ID <[email protected]>
--===============1211735220265590525==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_64BE05FD-A170-4ECF-8789-C8A6D97ACFAF"


--Apple-Mail=_64BE05FD-A170-4ECF-8789-C8A6D97ACFAF
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8


> =
https://plone.org/security/announcements/security-patch-released-20160830 =
<https://plone.org/security/announcements/security-patch-released-20160830=
>
>=20
> Security patch released: 20160830
>=20
> Hotfix to patch various vulnerabilities
>=20
> CVE numbers not yet issued.
>=20
> Versions Affected: All supported Plone versions (4.x, 5.x). Previous =
versions could be affected but have not been tested.
>=20
> Versions Not Affected: None.
>=20
> Nature of vulnerability: the patch will address several cross site =
scripting (XSS) vulnerability issues.
>=20
> The patch was released at 2016-08-30 15:00 UTC =
<http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2016&mo=3D8&d=
=3D30&h=3D15&mn=3D0>.
>=20
> Installation
>=20
> Full installation instructions are available on the HotFix release =
page <https://plone.org/security/hotfix/20160830>.
>=20
> Extra Help
>=20
> If you do not have in-house server administrators or a website =
maintenance service agreement, you can find consulting companies at =
plone.com/providers <http://plone.com/providers>=C2=A0 =
<https://old.plone.org/support/network>.
>=20
> There is also free support available online via the Plone IRC channel =
<http://plone.org/support> and the Plone community forum =
<http://community.plone.org/>.
>=20
> =20
>=20
> Questions and Answers
>=20
> What is involved in applying the patch?=20
> Patches are made available as tarball-style archives that may be =
unpacked into the =E2=80=9Cproducts=E2=80=9D folder of a buildout =
installation and as Python packages that may be installed by editing a =
buildout configuration file and running buildout. Patching is generally =
easy and quick to accomplish.
>=20
> How were these vulnerabilities found?
> The vulnerabilities were found by users submitting them to the =
security mailing list.
>=20
> My site is highly visible and mission-critical. I hear the patch has =
already been developed. Can I get the fix before the release date?=20
> Plone patches are always made available to all users at the same time. =
There are no exceptions.
>=20
> How can I report other potential security vulnerabilities?=20
> Please email the Plone Security Team at security-z4DKO/[email protected] =
<mailto:security-z4DKO/[email protected]> rather than publicly discussing potential =
security issues.
>=20
> How can I apply the patch without affecting my users?=20
> Even though this patch does NOT require you to run buildout, you can =
run buildout without affecting your users. You can restart a =
multi-client Plone install without affecting your users; see =
http://docs.plone.org/manage/deploying/processes.html =
<http://docs.plone.org/manage/deploying/processes.html> =20
>=20
> How do I get help patching my site?=20
> Plone service providers are listed at plone.com/providers=C2=A0 =
<http://plone.com/providers> There is also free support available online =
via the Plone IRC channel <http://plone.org/support> and the Plone =
community forum <http://community.plone.org/>.
>=20
> Who is on the Plone Security Team and how is it funded?
> The Plone Security Team is made up of volunteers who are experienced =
developers familiar with the Plone code base and with security exploits. =
The Plone Security Team is not funded; members and/or their employers =
have volunteered their time in the interests of the greater Plone =
community.
>=20
> How can I help the Plone Security Team?=20
> The Plone Security Team is looking for help from security-minded =
developers and testers. Volunteers must be known to the Security Team =
and have been part of the Plone community for some time. To help the =
Security Team financially, your donations are most welcome at =
https://plone.org/sponsors <https://plone.org/sponsors>.
>=20
> General questions about this announcement, Plone patching procedures, =
and availability of support may be addressed to the Plone support =
forums=C2=A0 <https://plone.org/support>. If you have specific questions =
about this vulnerability or its handling, contact the Plone Security =
Team=C2=A0 <mailto:security-z4DKO/[email protected]>directly.
>=20
> To report potentially security-related issues, e-mail the Plone =
Security Team directly at security-z4DKO/[email protected] <mailto:security-z4DKO/[email protected]> =
rather than publicly discussing potential security issues. We are always =
happy to credit individuals and companies who make responsible =
disclosures.
>=20
> The Plone Security Team is an all-volunteer team. If you'd like to =
help the team, as a developer, a tester, or as a financial sponsor, =
please email the team at security-z4DKO/[email protected] =
<mailto:security-z4DKO/[email protected]?subject=3Dsupport%20for%20the%20Plone%20Securit=
y%20Team> and become a sponsor at plone.org/sponsors =
<https://plone.org/sponsors>
> To be informed of future security patches, subscribe to the =
low-traffic Plone announcement list =
<https://lists.sourceforge.net/lists/listinfo/plone-announce>
> Information for Vulnerability Database Maintainers
>=20
> We have already applied for CVE numbers for these issues. Further =
information on individual vulnerabilities (including CVSS scores, CWE =
identifiers and summaries) is available at the current vulnerability =
list <https://plone.org/hotfixes> and the old vulnerability list =
<https://old.plone.org/products/plone/security/>=

--Apple-Mail=_64BE05FD-A170-4ECF-8789-C8A6D97ACFAF
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dutf-8"><base></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D""><base class=3D""><div =
class=3D"Apple-Mail-URLShareUserContentTopClass"><br class=3D""></div><div=
 class=3D"Apple-Mail-URLShareWrapperClass" style=3D"position: relative =
!important;"><blockquote type=3D"cite" style=3D"border-left-style: none; =
color: inherit; padding: inherit; margin: inherit;" class=3D""><div =
class=3D""><div class=3D"original-url"><a =
href=3D"https://plone.org/security/announcements/security-patch-released-2=
0160830" =
class=3D"">https://plone.org/security/announcements/security-patch-release=
d-20160830</a><br class=3D""><br class=3D""></div><div id=3D"article" =
role=3D"article" style=3D"-webkit-locale: en; border-bottom-width: 0px;" =
class=3D"">
        <!-- This node will contain a number of div.page. -->
    <div class=3D"page"><h1 class=3D"title">Security patch released: =
20160830</h1><header class=3D""><p class=3D"">Hotfix to patch various =
vulnerabilities</p>
           =20
          </header><p class=3D"">CVE numbers not yet issued.</p><p =
class=3D""><strong class=3D"">Versions Affected:</strong>&nbsp;All =
supported Plone versions (4.x, 5.x). Previous versions could be affected =
but have not been tested.</p><p class=3D""><strong class=3D"">Versions =
Not Affected:</strong>&nbsp;None.</p><p class=3D""><strong =
class=3D"">Nature of vulnerability:</strong>&nbsp;the patch will address =
several&nbsp;cross site scripting (XSS)&nbsp;vulnerability issues.</p><p =
class=3D""><strong class=3D"">The patch was&nbsp;released at&nbsp;<a =
href=3D"http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2016&a=
mp;mo=3D8&amp;d=3D30&amp;h=3D15&amp;mn=3D0" target=3D"_blank" =
data-linktype=3D"external" =
data-val=3D"http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D20=
16&amp;mo=3D8&amp;d=3D30&amp;h=3D15&amp;mn=3D0" class=3D"">2016-08-30 =
15:00 UTC</a>.</strong></p>
<h3 class=3D"">Installation</h3><p class=3D"">Full installation =
instructions are available on&nbsp;<a =
data-val=3D"2ad80d9ec77945209ec96731a4e4399c" =
href=3D"https://plone.org/security/hotfix/20160830" =
data-linktype=3D"internal" title=3D"Hotfix 20160830" class=3D"">the =
HotFix release page</a>.</p>
<h3 class=3D"">Extra Help</h3><p class=3D"">If you do not have in-house =
server administrators or a website maintenance service agreement, you =
can find consulting companies at&nbsp;<a title=3D"" =
href=3D"http://plone.com/providers" target=3D"_self" =
class=3D"">plone.com/providers</a><a =
href=3D"https://old.plone.org/support/network" =
class=3D"">&nbsp;</a>.</p><p class=3D"">There is also&nbsp;free =
support&nbsp;available online via the&nbsp;<a title=3D"" =
href=3D"http://plone.org/support" target=3D"_self" class=3D"">Plone IRC =
channel</a>&nbsp;and the&nbsp;<a title=3D"" =
href=3D"http://community.plone.org/" target=3D"_self" class=3D"">Plone =
community forum</a>.</p>
<h3 class=3D"">&nbsp;</h3>
<hr class=3D"">
<h2 class=3D"">Questions and Answers</h2><p class=3D""><strong =
class=3D"">What is involved in applying the patch?&nbsp;<br =
class=3D""></strong>Patches are made available as tarball-style archives =
that may be unpacked into the =E2=80=9Cproducts=E2=80=9D folder of a =
buildout installation and as Python packages that may be installed by =
editing a buildout configuration file and running buildout. Patching is =
generally easy and quick to accomplish.</p><p class=3D""><strong =
class=3D"">How were these vulnerabilities found?<br =
class=3D""></strong>The vulnerabilities were found by users submitting =
them to the security mailing list.</p><p class=3D""><strong class=3D"">My =
site is highly visible and mission-critical. I hear the patch has =
already been developed. Can I get the fix before the release =
date?&nbsp;</strong><br class=3D"">Plone patches are always made =
available to&nbsp;<strong class=3D"">all users at the same =
time</strong>. There are no exceptions.</p><p class=3D""><strong =
class=3D"">How can I report other potential security =
vulnerabilities?</strong>&nbsp;<br class=3D"">Please email the Plone =
Security Team at&nbsp;<a href=3D"mailto:security-z4DKO/[email protected]" =
class=3D"">security-z4DKO/[email protected]</a>&nbsp;rather than publicly discussing =
potential security issues.</p><p class=3D""><strong class=3D"">How can I =
apply the patch without affecting my users?</strong>&nbsp;<br =
class=3D"">Even though this patch does NOT require you to run buildout, =
you can run buildout without affecting your users. You can restart a =
multi-client Plone install without affecting your users; see&nbsp;<a =
href=3D"http://docs.plone.org/manage/deploying/processes.html" =
class=3D"">http://docs.plone.org/manage/deploying/processes.html</a>&nbsp;=
&nbsp;</p><p class=3D""><strong class=3D"">How do I get help patching my =
site?</strong>&nbsp;<br class=3D"">Plone service providers are listed =
at&nbsp;<a href=3D"http://plone.com/providers" =
class=3D"">plone.com/providers&nbsp;</a>&nbsp;There is also&nbsp;free =
support&nbsp;available online&nbsp;via the&nbsp;<a title=3D"" =
href=3D"http://plone.org/support" target=3D"_self" class=3D"">Plone IRC =
channel</a>&nbsp;and the&nbsp;<a title=3D"" =
href=3D"http://community.plone.org/" target=3D"_self" class=3D"">Plone =
community forum</a>.</p><p class=3D""><strong class=3D"">Who is on the =
Plone Security Team and how is it funded?</strong><br class=3D"">The =
Plone Security Team is made up of volunteers who are experienced =
developers familiar with the Plone code base and with security exploits. =
The Plone Security Team is not funded; members and/or their employers =
have volunteered their time in the interests of the greater Plone =
community.</p><p class=3D""><strong class=3D"">How can I help the Plone =
Security Team?</strong>&nbsp;<br class=3D"">The Plone Security Team is =
looking for help from&nbsp;security-minded developers and testers. =
Volunteers must be known to the Security Team and have been part of the =
Plone community for some time. To help the Security Team financially, =
your donations are most welcome at <a =
data-val=3D"https://plone.org/sponsors" =
href=3D"https://plone.org/../sponsors" data-linktype=3D"external" =
title=3D"Donate to support the Security Team!" =
class=3D"">https://plone.org/sponsors</a>.</p><p class=3D""><strong =
class=3D"">General questions&nbsp;</strong><strong class=3D"">about this =
announcement</strong>, Plone patching procedures, and availability of =
support may be addressed to the&nbsp;<a =
data-val=3D"https://plone.org/support" =
href=3D"https://plone.org/../support" data-linktype=3D"external" =
class=3D"">Plone support forums&nbsp;</a>. If you have&nbsp;<strong =
class=3D"">specific questions&nbsp;</strong>about this vulnerability or =
its handling, contact the&nbsp;<a href=3D"mailto:security-z4DKO/[email protected]" =
class=3D"">Plone Security Team&nbsp;</a>directly.</p><p class=3D""><strong=
 class=3D"">To report potentially security-related =
issues</strong><strong class=3D"">,&nbsp;</strong>e-mail the Plone =
Security Team directly at&nbsp;<a href=3D"mailto:security-z4DKO/[email protected]" =
class=3D"">security-z4DKO/[email protected]</a>&nbsp;rather than publicly discussing =
potential security issues.&nbsp;We are always happy to credit =
individuals and companies who make responsible disclosures.</p><p =
class=3D"">The Plone Security Team is an all-volunteer team. If you'd =
like to help the team, as a developer, a tester, or as a financial =
sponsor, please email the team at&nbsp;<a title=3D"" =
href=3D"mailto:security-z4DKO/[email protected]?subject=3Dsupport%20for%20the%20Plone%20=
Security%20Team" target=3D"_self" =
class=3D"">security-z4DKO/[email protected]</a>&nbsp;and become a sponsor at&nbsp;<a =
data-val=3D"https://plone.org/sponsors" =
href=3D"https://plone.org/../sponsors" data-linktype=3D"external" =
class=3D"">plone.org/sponsors</a></p><p class=3D""><strong class=3D"">To =
be informed of future security patches</strong>, subscribe to the =
low-traffic&nbsp;<a title=3D"" =
href=3D"https://lists.sourceforge.net/lists/listinfo/plone-announce" =
target=3D"_blank" class=3D"">Plone announcement list</a></p>
<h3 class=3D"">Information for Vulnerability Database Maintainers</h3><p =
class=3D"">We have already applied for CVE numbers for these issues. =
Further information on individual vulnerabilities (including CVSS =
scores, CWE identifiers and summaries) is available at the <a =
data-val=3D"https://plone.org/security/hotfixes" =
href=3D"https://plone.org/hotfixes" data-linktype=3D"external" =
class=3D"">current vulnerability list</a>&nbsp;and the&nbsp;<a =
href=3D"https://old.plone.org/products/plone/security/" class=3D"">old =
vulnerability =
list</a></p></div></div></div></blockquote></div></body></html>=

--Apple-Mail=_64BE05FD-A170-4ECF-8789-C8A6D97ACFAF--


--===============1211735220265590525==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------

--===============1211735220265590525==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Plone-Announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-announce

--===============1211735220265590525==--