Security patch released: 20161129 — Plone

"Announcement of Plone releases and security-related notifications. Recommended subscription for all Plone developers and site admins." <[email protected]> Tue, 29 Nov 2016 09:09:44 -0600
Newsgroups gmane.comp.web.zope.plone.announce
Message-ID <47B65975-9A3C-4FDC-ADF3-49AD082E24B0__4623.759041033$1480434560$gmane$org@plone.org>
--===============8554224589389227116==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_C9A6597D-ED4F-4B5A-9428-470E23D59A02"


--Apple-Mail=_C9A6597D-ED4F-4B5A-9428-470E23D59A02
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8


>=20
> =
https://plone.org/security/announcements/security-patch-released-20161129 =
<https://plone.org/security/announcements/security-patch-released-20161129=
>
>=20
> Security patch released: 20161129
> Hotfix to patch various vulnerabilities
>=20
> CVE numbers not yet issued.
>=20
> Versions Affected: All supported Plone versions (4.x, 5.x). Previous =
versions could be affected but have not been tested.
>=20
> Versions Not Affected: None.
>=20
> Nature of vulnerability: the patch will address several cross site =
scripting (XSS) and private data exposure vulnerabilities.
>=20
> The patch was released at 2016-11-29 15:00 UTC =
<http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2016&mo=3D11&=
d=3D29&h=3D15&mn=3D0>.
>=20
> Installation
>=20
> Full installation instructions are available on the HotFix release =
page <https://plone.org/security/hotfix/20161129>.
>=20
> Extra Help
>=20
> If you do not have in-house server administrators or a website =
maintenance service agreement, you can find consulting companies at =
plone.com/providers <http://plone.com/providers>=C2=A0 =
<https://old.plone.org/support/network>.
>=20
> There is also free support available online via the Plone IRC channel =
<http://plone.org/support> and the Plone community forum =
<http://community.plone.org/>.
>=20
> =20
>=20
> Questions and Answers
>=20
> What is involved in applying the patch?=20
> Patches are made available as tarball-style archives that may be =
unpacked into the =E2=80=9Cproducts=E2=80=9D folder of a buildout =
installation and as Python packages that may be installed by editing a =
buildout configuration file and running buildout. Patching is generally =
easy and quick to accomplish.
>=20
> How were these vulnerabilities found?
> The vulnerabilities were found by users submitting them to the =
security mailing list.
>=20
> My site is highly visible and mission-critical. I hear the patch has =
already been developed. Can I get the fix before the release date?=20
> Plone patches are always made available to all users at the same time. =
There are no exceptions.
>=20
> How can I report other potential security vulnerabilities?=20
> Please email the Plone Security Team at security-z4DKO/[email protected] =
<mailto:security-z4DKO/[email protected]> rather than publicly discussing potential =
security issues.
>=20
> How can I apply the patch without affecting my users?=20
> Even though this patch does NOT require you to run buildout, you can =
run buildout without affecting your users. You can restart a =
multi-client Plone install without affecting your users; see =
http://docs.plone.org/manage/deploying/processes.html =
<http://docs.plone.org/manage/deploying/processes.html> =20
>=20
> How do I get help patching my site?=20
> Plone service providers are listed at plone.com/providers=C2=A0 =
<http://plone.com/providers> There is also free support available online =
via the Plone IRC channel <http://plone.org/support> and the Plone =
community forum <http://community.plone.org/>.
>=20
> Who is on the Plone Security Team and how is it funded?
> The Plone Security Team is made up of volunteers who are experienced =
developers familiar with the Plone code base and with security exploits. =
The Plone Security Team is not funded; members and/or their employers =
have volunteered their time in the interests of the greater Plone =
community.
>=20
> How can I help the Plone Security Team?=20
> The Plone Security Team is looking for help from security-minded =
developers and testers. Volunteers must be known to the Security Team =
and have been part of the Plone community for some time. To help the =
Security Team financially, your donations are most welcome at =
https://plone.org/sponsors <https://plone.org/sponsors>.
>=20
> General questions about this announcement, Plone patching procedures, =
and availability of support may be addressed to the Plone support =
forums=C2=A0 <https://plone.org/support>. If you have specific questions =
about this vulnerability or its handling, contact the Plone Security =
Team=C2=A0 <mailto:security-z4DKO/[email protected]>directly.
>=20
> To report potentially security-related issues, e-mail the Plone =
Security Team directly at security-z4DKO/[email protected] <mailto:security-z4DKO/[email protected]> =
rather than publicly discussing potential security issues. We are always =
happy to credit individuals and companies who make responsible =
disclosures.
>=20
> The Plone Security Team is an all-volunteer team. If you'd like to =
help the team, as a developer, a tester, or as a financial sponsor, =
please email the team at security-z4DKO/[email protected] =
<mailto:security-z4DKO/[email protected]?subject=3Dsupport%20for%20the%20Plone%20Securit=
y%20Team> and become a sponsor at plone.org/sponsors =
<https://plone.org/sponsors>
> To be informed of future security patches, subscribe to the =
low-traffic Plone announcement list =
<https://lists.sourceforge.net/lists/listinfo/plone-announce>
> Information for Vulnerability Database Maintainers
>=20
> We have already applied for CVE numbers for these issues. Further =
information on individual vulnerabilities (including CVSS scores, CWE =
identifiers and summaries) is available at the current vulnerability =
list <https://plone.org/hotfixes> and the old vulnerability list =
<https://old.plone.org/products/plone/security/>



--Apple-Mail=_C9A6597D-ED4F-4B5A-9428-470E23D59A02
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dutf-8"><base></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D""><base class=3D""><div =
class=3D"Apple-Mail-URLShareUserContentTopClass"><br class=3D""></div><div=
 class=3D"Apple-Mail-URLShareWrapperClass" style=3D"position: relative =
!important;"><blockquote type=3D"cite" style=3D"border-left-style: none; =
color: inherit; padding: inherit; margin: inherit;" class=3D""><div =
class=3D""><div class=3D"original-url"><br class=3D""><a =
href=3D"https://plone.org/security/announcements/security-patch-released-2=
0161129" =
class=3D"">https://plone.org/security/announcements/security-patch-release=
d-20161129</a><br class=3D""><br class=3D""></div><div id=3D"article" =
role=3D"article" style=3D"text-rendering: optimizelegibility; =
font-family: -apple-system-font; font-size: 1.2em; line-height: 1.5em; =
margin: 0px; padding: 0px;" class=3D"system exported">
        <!-- This node will contain a number of div.page. -->
    <div class=3D"page" style=3D"word-wrap: break-word; max-width: =
100%;"><h1 class=3D"title" style=3D"font-weight: 400; line-height: =
1.2em; margin-top: 0px; margin-bottom: 0.5em; -webkit-hyphens: manual; =
max-width: 100%;">Security patch released: 20161129</h1><h2 =
class=3D"subhead" style=3D"font-weight: 400; -webkit-hyphens: manual; =
color: rgba(27, 27, 27, 0.65098); margin-top: -0.35em; line-height: =
1.27em; max-width: 100%;">Hotfix to patch various vulnerabilities</h2><p =
style=3D"max-width: 100%;" class=3D"">CVE numbers not yet issued.</p><p =
style=3D"max-width: 100%;" class=3D""><strong style=3D"max-width: 100%;" =
class=3D"">Versions Affected:</strong>&nbsp;All supported Plone versions =
(4.x, 5.x). Previous versions could be affected but have not been =
tested.</p><p style=3D"max-width: 100%;" class=3D""><strong =
style=3D"max-width: 100%;" class=3D"">Versions Not =
Affected:</strong>&nbsp;None.</p><p style=3D"max-width: 100%;" =
class=3D""><strong style=3D"max-width: 100%;" class=3D"">Nature of =
vulnerability:</strong>&nbsp;the patch will address several&nbsp;cross =
site scripting (XSS) and private data exposure vulnerabilities.</p><p =
style=3D"max-width: 100%;" class=3D""><strong style=3D"max-width: 100%;" =
class=3D"">The patch was&nbsp;released at&nbsp;<a =
href=3D"http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2016&a=
mp;mo=3D11&amp;d=3D29&amp;h=3D15&amp;mn=3D0" target=3D"_blank" =
data-linktype=3D"external" =
data-val=3D"http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D20=
16&amp;mo=3D11&amp;d=3D29&amp;h=3D15&amp;mn=3D0" style=3D"color: rgb(65, =
110, 210); max-width: 100%;" class=3D"">2016-11-29 15:00 =
UTC</a>.</strong></p>
<h3 style=3D"font-size: 1.05em; max-width: 100%;" =
class=3D"">Installation</h3><p style=3D"max-width: 100%;" class=3D"">Full =
installation instructions are available on&nbsp;<a =
data-val=3D"ee6a2f2bc8e042daa3d167f6fb28bbda" =
href=3D"https://plone.org/security/hotfix/20161129" =
data-linktype=3D"internal" title=3D"Hotfix 20161129" style=3D"color: =
rgb(65, 110, 210); max-width: 100%;" class=3D"">the HotFix release =
page</a>.</p>
<h3 style=3D"font-size: 1.05em; max-width: 100%;" class=3D"">Extra =
Help</h3><p style=3D"max-width: 100%;" class=3D"">If you do not have =
in-house server administrators or a website maintenance service =
agreement, you can find consulting companies at&nbsp;<a title=3D"" =
href=3D"http://plone.com/providers" target=3D"_self" style=3D"color: =
rgb(65, 110, 210); max-width: 100%;" class=3D"">plone.com/providers</a><a =
href=3D"https://old.plone.org/support/network" style=3D"color: rgb(65, =
110, 210); max-width: 100%;" class=3D"">&nbsp;</a>.</p><p =
style=3D"max-width: 100%;" class=3D"">There is also&nbsp;free =
support&nbsp;available online via the&nbsp;<a title=3D"" =
href=3D"http://plone.org/support" target=3D"_self" style=3D"color: =
rgb(65, 110, 210); max-width: 100%;" class=3D"">Plone IRC =
channel</a>&nbsp;and the&nbsp;<a title=3D"" =
href=3D"http://community.plone.org/" target=3D"_self" style=3D"color: =
rgb(65, 110, 210); max-width: 100%;" class=3D"">Plone community =
forum</a>.</p>
<h3 style=3D"font-size: 1.05em; max-width: 100%;" class=3D"">&nbsp;</h3>
<hr style=3D"max-width: 100%; background-color: rgba(0, 0, 0, 0.2); =
height: 1px; border: 0px;" class=3D"">
<h2 style=3D"font-size: 1.125em; max-width: 100%;" class=3D"">Questions =
and Answers</h2><p style=3D"max-width: 100%;" class=3D""><strong =
style=3D"max-width: 100%;" class=3D"">What is involved in applying the =
patch?&nbsp;<br style=3D"max-width: 100%;" class=3D""></strong>Patches =
are made available as tarball-style archives that may be unpacked into =
the =E2=80=9Cproducts=E2=80=9D folder of a buildout installation and as =
Python packages that may be installed by editing a buildout =
configuration file and running buildout. Patching is generally easy and =
quick to accomplish.</p><p style=3D"max-width: 100%;" class=3D""><strong =
style=3D"max-width: 100%;" class=3D"">How were these vulnerabilities =
found?<br style=3D"max-width: 100%;" class=3D""></strong>The =
vulnerabilities were found by users submitting them to the security =
mailing list.</p><p style=3D"max-width: 100%;" class=3D""><strong =
style=3D"max-width: 100%;" class=3D"">My site is highly visible and =
mission-critical. I hear the patch has already been developed. Can I get =
the fix before the release date?&nbsp;</strong><br style=3D"max-width: =
100%;" class=3D"">Plone patches are always made available =
to&nbsp;<strong style=3D"max-width: 100%;" class=3D"">all users at the =
same time</strong>. There are no exceptions.</p><p style=3D"max-width: =
100%;" class=3D""><strong style=3D"max-width: 100%;" class=3D"">How can =
I report other potential security vulnerabilities?</strong>&nbsp;<br =
style=3D"max-width: 100%;" class=3D"">Please email the Plone Security =
Team at&nbsp;<a href=3D"mailto:security-z4DKO/[email protected]" style=3D"color: =
rgb(65, 110, 210); max-width: 100%;" =
class=3D"">security-z4DKO/[email protected]</a>&nbsp;rather than publicly discussing =
potential security issues.</p><p style=3D"max-width: 100%;" =
class=3D""><strong style=3D"max-width: 100%;" class=3D"">How can I apply =
the patch without affecting my users?</strong>&nbsp;<br =
style=3D"max-width: 100%;" class=3D"">Even though this patch does NOT =
require you to run buildout, you can run buildout without affecting your =
users. You can restart a multi-client Plone install without affecting =
your users; see&nbsp;<a =
href=3D"http://docs.plone.org/manage/deploying/processes.html" =
style=3D"color: rgb(65, 110, 210); max-width: 100%;" =
class=3D"">http://docs.plone.org/manage/deploying/processes.html</a>&nbsp;=
&nbsp;</p><p style=3D"max-width: 100%;" class=3D""><strong =
style=3D"max-width: 100%;" class=3D"">How do I get help patching my =
site?</strong>&nbsp;<br style=3D"max-width: 100%;" class=3D"">Plone =
service providers are listed at&nbsp;<a =
href=3D"http://plone.com/providers" style=3D"color: rgb(65, 110, 210); =
max-width: 100%;" class=3D"">plone.com/providers&nbsp;</a>&nbsp;There is =
also&nbsp;free support&nbsp;available online&nbsp;via the&nbsp;<a =
title=3D"" href=3D"http://plone.org/support" target=3D"_self" =
style=3D"color: rgb(65, 110, 210); max-width: 100%;" class=3D"">Plone =
IRC channel</a>&nbsp;and the&nbsp;<a title=3D"" =
href=3D"http://community.plone.org/" target=3D"_self" style=3D"color: =
rgb(65, 110, 210); max-width: 100%;" class=3D"">Plone community =
forum</a>.</p><p style=3D"max-width: 100%;" class=3D""><strong =
style=3D"max-width: 100%;" class=3D"">Who is on the Plone Security Team =
and how is it funded?</strong><br style=3D"max-width: 100%;" =
class=3D"">The Plone Security Team is made up of volunteers who are =
experienced developers familiar with the Plone code base and with =
security exploits. The Plone Security Team is not funded; members and/or =
their employers have volunteered their time in the interests of the =
greater Plone community.</p><p style=3D"max-width: 100%;" =
class=3D""><strong style=3D"max-width: 100%;" class=3D"">How can I help =
the Plone Security Team?</strong>&nbsp;<br style=3D"max-width: 100%;" =
class=3D"">The Plone Security Team is looking for help =
from&nbsp;security-minded developers and testers. Volunteers must be =
known to the Security Team and have been part of the Plone community for =
some time. To help the Security Team financially, your donations are =
most welcome at <a data-val=3D"https://plone.org/sponsors" =
href=3D"https://plone.org/../sponsors" data-linktype=3D"external" =
title=3D"Donate to support the Security Team!" style=3D"color: rgb(65, =
110, 210); max-width: 100%;" =
class=3D"">https://plone.org/sponsors</a>.</p><p style=3D"max-width: =
100%;" class=3D""><strong style=3D"max-width: 100%;" class=3D"">General =
questions&nbsp;</strong><strong style=3D"max-width: 100%;" =
class=3D"">about this announcement</strong>, Plone patching procedures, =
and availability of support may be addressed to the&nbsp;<a =
data-val=3D"https://plone.org/support" =
href=3D"https://plone.org/../support" data-linktype=3D"external" =
style=3D"color: rgb(65, 110, 210); max-width: 100%;" class=3D"">Plone =
support forums&nbsp;</a>. If you have&nbsp;<strong style=3D"max-width: =
100%;" class=3D"">specific questions&nbsp;</strong>about this =
vulnerability or its handling, contact the&nbsp;<a =
href=3D"mailto:security-z4DKO/[email protected]" style=3D"color: rgb(65, 110, 210); =
max-width: 100%;" class=3D"">Plone Security =
Team&nbsp;</a>directly.</p><p style=3D"max-width: 100%;" =
class=3D""><strong style=3D"max-width: 100%;" class=3D"">To report =
potentially security-related issues</strong><strong style=3D"max-width: =
100%;" class=3D"">,&nbsp;</strong>e-mail the Plone Security Team =
directly at&nbsp;<a href=3D"mailto:security-z4DKO/[email protected]" style=3D"color: =
rgb(65, 110, 210); max-width: 100%;" =
class=3D"">security-z4DKO/[email protected]</a>&nbsp;rather than publicly discussing =
potential security issues.&nbsp;We are always happy to credit =
individuals and companies who make responsible disclosures.</p><p =
style=3D"max-width: 100%;" class=3D"">The Plone Security Team is an =
all-volunteer team. If you'd like to help the team, as a developer, a =
tester, or as a financial sponsor, please email the team at&nbsp;<a =
title=3D"" =
href=3D"mailto:security-z4DKO/[email protected]?subject=3Dsupport%20for%20the%20Plone%20=
Security%20Team" target=3D"_self" style=3D"color: rgb(65, 110, 210); =
max-width: 100%;" class=3D"">security-z4DKO/[email protected]</a>&nbsp;and become a =
sponsor at&nbsp;<a data-val=3D"https://plone.org/sponsors" =
href=3D"https://plone.org/../sponsors" data-linktype=3D"external" =
style=3D"color: rgb(65, 110, 210); max-width: 100%;" =
class=3D"">plone.org/sponsors</a></p><p style=3D"max-width: 100%;" =
class=3D""><strong style=3D"max-width: 100%;" class=3D"">To be informed =
of future security patches</strong>, subscribe to the =
low-traffic&nbsp;<a title=3D"" =
href=3D"https://lists.sourceforge.net/lists/listinfo/plone-announce" =
target=3D"_blank" style=3D"color: rgb(65, 110, 210); max-width: 100%;" =
class=3D"">Plone announcement list</a></p>
<h3 style=3D"font-size: 1.05em; max-width: 100%;" class=3D"">Information =
for Vulnerability Database Maintainers</h3><p style=3D"max-width: 100%;" =
class=3D"">We have already applied for CVE numbers for these issues. =
Further information on individual vulnerabilities (including CVSS =
scores, CWE identifiers and summaries) is available at the <a =
data-val=3D"https://plone.org/security/hotfixes" =
href=3D"https://plone.org/hotfixes" data-linktype=3D"external" =
style=3D"color: rgb(65, 110, 210); max-width: 100%;" class=3D"">current =
vulnerability list</a>&nbsp;and the&nbsp;<a =
href=3D"https://old.plone.org/products/plone/security/" style=3D"color: =
rgb(65, 110, 210); max-width: 100%;" class=3D"">old vulnerability =
list</a></p></div></div></div></blockquote></div><br class=3D""><br =
class=3D"">
<br class=3D""></body></html>=

--Apple-Mail=_C9A6597D-ED4F-4B5A-9428-470E23D59A02--


--===============8554224589389227116==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------

--===============8554224589389227116==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Plone-Announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-announce

--===============8554224589389227116==--