Plone security patch released: 20170117
"Announcement of Plone releases and security-related notifications. Recommended subscription for all Plone developers and site admins." <[email protected]> Tue, 17 Jan 2017 08:56:38 -0600
| Newsgroups | gmane.comp.web.zope.plone.announce |
|---|---|
| Message-ID | <[email protected]> |
--===============7517648016273322372== Content-Type: multipart/alternative; boundary="Apple-Mail=_ACD08F36-4BD1-44BA-9414-F6CEC3AFEE49" --Apple-Mail=_ACD08F36-4BD1-44BA-9414-F6CEC3AFEE49 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 >=20 >=20 = https://plone.org/security/announcements/security-patch-released-20170117 = <https://plone.org/security/announcements/security-patch-released-20170117= > >=20 > Security patch released: 20170117 > Hotfix to patch XSS and sandbox escape vulnerability >=20 > This is a routine patch with our standard 14 day notice period. There = is no evidence that the issues fixed here are being used against any = sites. >=20 > CVE numbers: CVE-2016-7147 = <http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2016-7147> and one = not yet issued. >=20 > Versions Affected: All supported Plone versions (4.3.11 and any = earlier 4.x version, 5.0.6 and any earlier 5.x version). Previous = versions could be affected but have not been fully tested. >=20 > Versions Not Affected: None. >=20 > Nature of vulnerability: the patch will address a reflected XSS = vulnerability in Zope and a partial sandbox escape vulnerability = available to system administrators. >=20 > Version support: The hotfix is officially supported by the Plone = security team on the following versions of Plone in accordance with the = Plone version support policy: 4.0.10, 4.1.6, 4.2.7, 4.3.11 and 5.0.6. = However, it has also received some testing on older versions of Plone. >=20 > The fixes included here will be incorporated into subsequent releases = of Plone, so Plone 4.3.12, 5.0.7 and greater should not require this = hotfix. >=20 > Credit: Thanks to Tim Coen of Curesec GmbH for the responsible = disclosure of the XSS vulnerability. The partial sandbox escape was = found by the Plone security team, inspired by Armin Ronacher's writings = on the subject. >=20 > The patch was released at 2017-01-17 15:00 UTC = <http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2017&mo=3D1&d= =3D17&h=3D15&mn=3D0>. >=20 > Installation >=20 > Full installation instructions are available on the HotFix release = page <https://plone.org/security/hotfix/20170117>. >=20 > Extra Help >=20 > If you do not have in-house server administrators or a website = maintenance service agreement, you can find consulting companies at = plone.com/providers <http://plone.com/providers>=C2=A0 = <https://old.plone.org/support/network>. >=20 > There is also free support available online via the Plone = chat=C2=A0channels <http://plone.org/support> and the Plone community = forum <http://community.plone.org/>. >=20 > =20 >=20 > Questions and Answers >=20 > What is involved in applying the patch?=20 > Patches are made available as tarball-style archives that may be = unpacked into the =E2=80=9Cproducts=E2=80=9D folder of a buildout = installation and as Python packages that may be installed by editing a = buildout configuration file and running buildout. Patching is generally = easy and quick to accomplish. >=20 > How were these vulnerabilities found? > The vulnerabilities were found by users submitting them to the = security mailing list. >=20 > My site is highly visible and mission-critical. I hear the patch has = already been developed. Can I get the fix before the release date?=20 > Plone patches are always made available to all users at the same time. = There are no exceptions. >=20 > How can I report other potential security vulnerabilities?=20 > Please email the Plone Security Team at security-z4DKO/[email protected] = <mailto:security-z4DKO/[email protected]> rather than publicly discussing potential = security issues. >=20 > How can I apply the patch without affecting my users?=20 > Even though this patch does NOT require you to run buildout, you can = run buildout without affecting your users. You can restart a = multi-client Plone install without affecting your users; see = http://docs.plone.org/manage/deploying/processes.html = <http://docs.plone.org/manage/deploying/processes.html> =20 >=20 > How do I get help patching my site?=20 > Plone service providers are listed at plone.com/providers=C2=A0 = <http://plone.com/providers> There is also free support available online = via the Plone IRC channel <http://plone.org/support> and the Plone = community forum <http://community.plone.org/>. >=20 > Who is on the Plone Security Team and how is it funded? > The Plone Security Team is made up of volunteers who are experienced = developers familiar with the Plone code base and with security exploits. = The Plone Security Team is not funded; members and/or their employers = have volunteered their time in the interests of the greater Plone = community. >=20 > How can I help the Plone Security Team?=20 > The Plone Security Team is looking for help from security-minded = developers and testers. Volunteers must be known to the Security Team = and have been part of the Plone community for some time. To help the = Security Team financially, your donations are most welcome at = https://plone.org/sponsors <https://plone.org/sponsors>. >=20 > General questions about this announcement, Plone patching procedures, = and availability of support may be addressed to the Plone support = forums=C2=A0 <https://plone.org/support>. If you have specific questions = about this vulnerability or its handling, contact the Plone Security = Team=C2=A0 <mailto:security-z4DKO/[email protected]>directly. >=20 > To report potentially security-related issues, e-mail the Plone = Security Team directly at security-z4DKO/[email protected] <mailto:security-z4DKO/[email protected]> = rather than publicly discussing potential security issues. We are always = happy to credit individuals and companies who make responsible = disclosures. >=20 > The Plone Security Team is an all-volunteer team. If you'd like to = help the team, as a developer, a tester, or as a financial sponsor, = please email the team at security-z4DKO/[email protected] = <mailto:security-z4DKO/[email protected]?subject=3Dsupport%20for%20the%20Plone%20Securit= y%20Team> and become a sponsor at plone.org/sponsors = <https://plone.org/sponsors> > To be informed of future security patches, subscribe to the = low-traffic Plone announcement list = <https://lists.sourceforge.net/lists/listinfo/plone-announce> > Information for Vulnerability Database Maintainers >=20 > We have already applied for CVE numbers for these issues. Further = information on individual vulnerabilities (including CVSS scores, CWE = identifiers and summaries) is available at the current vulnerability = list <https://plone.org/hotfixes> and the old vulnerability list = <https://old.plone.org/products/plone/security/>= --Apple-Mail=_ACD08F36-4BD1-44BA-9414-F6CEC3AFEE49 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 <html><head><meta http-equiv=3D"Content-Type" content=3D"text/html = charset=3Dutf-8"><base></head><body style=3D"word-wrap: break-word; = -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" = class=3D""><base class=3D""><div = class=3D"Apple-Mail-URLShareUserContentTopClass"><br class=3D""></div><div= class=3D"Apple-Mail-URLShareWrapperClass" style=3D"position: relative = !important;"><blockquote type=3D"cite" style=3D"border-left-style: none; = color: inherit; padding: inherit; margin: inherit;" class=3D""><div = class=3D""><div class=3D"original-url"><br class=3D""><br = class=3D""></div></div></blockquote><a = href=3D"https://plone.org/security/announcements/security-patch-released-2= 0170117" = class=3D"">https://plone.org/security/announcements/security-patch-release= d-20170117</a><blockquote type=3D"cite" style=3D"border-left-style: = none; color: inherit; padding: inherit; margin: inherit;" class=3D""><div = class=3D""><div class=3D"original-url"><br class=3D""></div><div = id=3D"article" role=3D"article" style=3D"text-rendering: = optimizelegibility; font-family: -apple-system-font; font-size: 1.2em; = line-height: 1.5em; margin: 0px; padding: 0px;" class=3D"system = exported"> <!-- This node will contain a number of div.page. --> <div class=3D"page" style=3D"word-wrap: break-word; max-width: = 100%;"><h1 class=3D"title" style=3D"font-weight: 400; line-height: = 1.2em; margin-top: 0px; margin-bottom: 0.5em; -webkit-hyphens: manual; = max-width: 100%;">Security patch released: 20170117</h1><h2 = class=3D"subhead" style=3D"font-weight: 400; -webkit-hyphens: manual; = color: rgba(27, 27, 27, 0.65098); margin-top: -0.35em; line-height: = 1.27em; max-width: 100%;">Hotfix to patch XSS and sandbox escape = vulnerability</h2><p style=3D"max-width: 100%;" class=3D""><em = style=3D"max-width: 100%;" class=3D"">This is a routine patch with our = standard 14 day notice period. There is no evidence that the issues = fixed here are being used against any sites.</em></p><p = style=3D"max-width: 100%;" class=3D"">CVE numbers: <a = href=3D"http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2016-7147" = style=3D"color: rgb(65, 110, 210); max-width: 100%;" = class=3D"">CVE-2016-7147</a> and one not yet issued.</p><p = style=3D"max-width: 100%;" class=3D""><strong style=3D"max-width: 100%;" = class=3D"">Versions Affected:</strong> All supported Plone versions = (4.3.11 and any earlier 4.x version, 5.0.6 and any earlier 5.x version). = Previous versions could be affected but have not been fully = tested.</p><p style=3D"max-width: 100%;" class=3D""><strong = style=3D"max-width: 100%;" class=3D"">Versions Not = Affected:</strong> None.</p><p style=3D"max-width: 100%;" = class=3D""><strong style=3D"max-width: 100%;" class=3D"">Nature of = vulnerability:</strong> the patch will address a reflected XSS = vulnerability in Zope and a partial sandbox escape vulnerability = available to system administrators.</p><p style=3D"max-width: 100%;" = class=3D""><strong style=3D"max-width: 100%;" class=3D"">Version = support:</strong> The hotfix is officially supported by the Plone = security team on the following versions of Plone in accordance with the = Plone version support policy: 4.0.10, 4.1.6, 4.2.7, 4.3.11 and 5.0.6. = However, it has also received some testing on older versions of = Plone.</p><p style=3D"max-width: 100%;" class=3D"">The fixes included = here will be incorporated into subsequent releases of Plone, so Plone = 4.3.12, 5.0.7 and greater should not require this hotfix.</p><p = style=3D"max-width: 100%;" class=3D""><strong style=3D"max-width: 100%;" = class=3D"">Credit:</strong> Thanks to Tim Coen of Curesec GmbH for the = responsible disclosure of the XSS vulnerability. The partial sandbox = escape was found by the Plone security team, inspired by Armin = Ronacher's writings on the subject.</p><p style=3D"max-width: 100%;" = class=3D""><strong style=3D"max-width: 100%;" class=3D"">The patch = was released at <a = href=3D"http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2017&a= mp;mo=3D1&d=3D17&h=3D15&mn=3D0" target=3D"_blank" = data-linktype=3D"external" = data-val=3D"http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D20= 17&mo=3D1&d=3D17&h=3D15&mn=3D0" style=3D"color: rgb(65, = 110, 210); max-width: 100%;" class=3D"">2017-01-17 15:00 = UTC</a>.</strong></p> <h3 style=3D"font-size: 1.05em; max-width: 100%;" = class=3D"">Installation</h3><p style=3D"max-width: 100%;" class=3D"">Full = installation instructions are available on <a = data-val=3D"0a5ee8f69b49479c9df8a109eb4fddd5" = href=3D"https://plone.org/security/hotfix/20170117" = data-linktype=3D"internal" title=3D"Hotfix 20170117" style=3D"color: = rgb(65, 110, 210); max-width: 100%;" class=3D"">the HotFix release = page</a>.</p> <h3 style=3D"font-size: 1.05em; max-width: 100%;" class=3D"">Extra = Help</h3><p style=3D"max-width: 100%;" class=3D"">If you do not have = in-house server administrators or a website maintenance service = agreement, you can find consulting companies at <a title=3D"" = href=3D"http://plone.com/providers" target=3D"_self" style=3D"color: = rgb(65, 110, 210); max-width: 100%;" class=3D"">plone.com/providers</a><a = href=3D"https://old.plone.org/support/network" style=3D"color: rgb(65, = 110, 210); max-width: 100%;" class=3D""> </a>.</p><p = style=3D"max-width: 100%;" class=3D"">There is also free = support available online via the <a title=3D"" = href=3D"http://plone.org/support" target=3D"_self" style=3D"color: = rgb(65, 110, 210); max-width: 100%;" class=3D"">Plone = chat channels</a> and the <a title=3D"" = href=3D"http://community.plone.org/" target=3D"_self" style=3D"color: = rgb(65, 110, 210); max-width: 100%;" class=3D"">Plone community = forum</a>.</p> <h3 style=3D"font-size: 1.05em; max-width: 100%;" class=3D""> </h3> <hr style=3D"max-width: 100%; background-color: rgba(0, 0, 0, 0.2); = height: 1px; border: 0px;" class=3D""> <h2 style=3D"font-size: 1.125em; max-width: 100%;" class=3D"">Questions = and Answers</h2><p style=3D"max-width: 100%;" class=3D""><strong = style=3D"max-width: 100%;" class=3D"">What is involved in applying the = patch? <br style=3D"max-width: 100%;" class=3D""></strong>Patches = are made available as tarball-style archives that may be unpacked into = the =E2=80=9Cproducts=E2=80=9D folder of a buildout installation and as = Python packages that may be installed by editing a buildout = configuration file and running buildout. Patching is generally easy and = quick to accomplish.</p><p style=3D"max-width: 100%;" class=3D""><strong = style=3D"max-width: 100%;" class=3D"">How were these vulnerabilities = found?<br style=3D"max-width: 100%;" class=3D""></strong>The = vulnerabilities were found by users submitting them to the security = mailing list.</p><p style=3D"max-width: 100%;" class=3D""><strong = style=3D"max-width: 100%;" class=3D"">My site is highly visible and = mission-critical. I hear the patch has already been developed. Can I get = the fix before the release date? </strong><br style=3D"max-width: = 100%;" class=3D"">Plone patches are always made available = to <strong style=3D"max-width: 100%;" class=3D"">all users at the = same time</strong>. There are no exceptions.</p><p style=3D"max-width: = 100%;" class=3D""><strong style=3D"max-width: 100%;" class=3D"">How can = I report other potential security vulnerabilities?</strong> <br = style=3D"max-width: 100%;" class=3D"">Please email the Plone Security = Team at <a href=3D"mailto:security-z4DKO/[email protected]" style=3D"color: = rgb(65, 110, 210); max-width: 100%;" = class=3D"">security-z4DKO/[email protected]</a> rather than publicly discussing = potential security issues.</p><p style=3D"max-width: 100%;" = class=3D""><strong style=3D"max-width: 100%;" class=3D"">How can I apply = the patch without affecting my users?</strong> <br = style=3D"max-width: 100%;" class=3D"">Even though this patch does NOT = require you to run buildout, you can run buildout without affecting your = users. You can restart a multi-client Plone install without affecting = your users; see <a = href=3D"http://docs.plone.org/manage/deploying/processes.html" = style=3D"color: rgb(65, 110, 210); max-width: 100%;" = class=3D"">http://docs.plone.org/manage/deploying/processes.html</a> = </p><p style=3D"max-width: 100%;" class=3D""><strong = style=3D"max-width: 100%;" class=3D"">How do I get help patching my = site?</strong> <br style=3D"max-width: 100%;" class=3D"">Plone = service providers are listed at <a = href=3D"http://plone.com/providers" style=3D"color: rgb(65, 110, 210); = max-width: 100%;" class=3D"">plone.com/providers </a> There is = also free support available online via the <a = title=3D"" href=3D"http://plone.org/support" target=3D"_self" = style=3D"color: rgb(65, 110, 210); max-width: 100%;" class=3D"">Plone = IRC channel</a> and the <a title=3D"" = href=3D"http://community.plone.org/" target=3D"_self" style=3D"color: = rgb(65, 110, 210); max-width: 100%;" class=3D"">Plone community = forum</a>.</p><p style=3D"max-width: 100%;" class=3D""><strong = style=3D"max-width: 100%;" class=3D"">Who is on the Plone Security Team = and how is it funded?</strong><br style=3D"max-width: 100%;" = class=3D"">The Plone Security Team is made up of volunteers who are = experienced developers familiar with the Plone code base and with = security exploits. The Plone Security Team is not funded; members and/or = their employers have volunteered their time in the interests of the = greater Plone community.</p><p style=3D"max-width: 100%;" = class=3D""><strong style=3D"max-width: 100%;" class=3D"">How can I help = the Plone Security Team?</strong> <br style=3D"max-width: 100%;" = class=3D"">The Plone Security Team is looking for help = from security-minded developers and testers. Volunteers must be = known to the Security Team and have been part of the Plone community for = some time. To help the Security Team financially, your donations are = most welcome at <a data-val=3D"https://plone.org/sponsors" = href=3D"https://plone.org/../sponsors" data-linktype=3D"external" = title=3D"Donate to support the Security Team!" style=3D"color: rgb(65, = 110, 210); max-width: 100%;" = class=3D"">https://plone.org/sponsors</a>.</p><p style=3D"max-width: = 100%;" class=3D""><strong style=3D"max-width: 100%;" class=3D"">General = questions </strong><strong style=3D"max-width: 100%;" = class=3D"">about this announcement</strong>, Plone patching procedures, = and availability of support may be addressed to the <a = data-val=3D"https://plone.org/support" = href=3D"https://plone.org/../support" data-linktype=3D"external" = style=3D"color: rgb(65, 110, 210); max-width: 100%;" class=3D"">Plone = support forums </a>. If you have <strong style=3D"max-width: = 100%;" class=3D"">specific questions </strong>about this = vulnerability or its handling, contact the <a = href=3D"mailto:security-z4DKO/[email protected]" style=3D"color: rgb(65, 110, 210); = max-width: 100%;" class=3D"">Plone Security = Team </a>directly.</p><p style=3D"max-width: 100%;" = class=3D""><strong style=3D"max-width: 100%;" class=3D"">To report = potentially security-related issues</strong><strong style=3D"max-width: = 100%;" class=3D"">, </strong>e-mail the Plone Security Team = directly at <a href=3D"mailto:security-z4DKO/[email protected]" style=3D"color: = rgb(65, 110, 210); max-width: 100%;" = class=3D"">security-z4DKO/[email protected]</a> rather than publicly discussing = potential security issues. We are always happy to credit = individuals and companies who make responsible disclosures.</p><p = style=3D"max-width: 100%;" class=3D"">The Plone Security Team is an = all-volunteer team. If you'd like to help the team, as a developer, a = tester, or as a financial sponsor, please email the team at <a = title=3D"" = href=3D"mailto:security-z4DKO/[email protected]?subject=3Dsupport%20for%20the%20Plone%20= Security%20Team" target=3D"_self" style=3D"color: rgb(65, 110, 210); = max-width: 100%;" class=3D"">security-z4DKO/[email protected]</a> and become a = sponsor at <a data-val=3D"https://plone.org/sponsors" = href=3D"https://plone.org/../sponsors" data-linktype=3D"external" = style=3D"color: rgb(65, 110, 210); max-width: 100%;" = class=3D"">plone.org/sponsors</a></p><p style=3D"max-width: 100%;" = class=3D""><strong style=3D"max-width: 100%;" class=3D"">To be informed = of future security patches</strong>, subscribe to the = low-traffic <a title=3D"" = href=3D"https://lists.sourceforge.net/lists/listinfo/plone-announce" = target=3D"_blank" style=3D"color: rgb(65, 110, 210); max-width: 100%;" = class=3D"">Plone announcement list</a></p> <h3 style=3D"font-size: 1.05em; max-width: 100%;" class=3D"">Information = for Vulnerability Database Maintainers</h3><p style=3D"max-width: 100%;" = class=3D"">We have already applied for CVE numbers for these issues. = Further information on individual vulnerabilities (including CVSS = scores, CWE identifiers and summaries) is available at the <a = data-val=3D"https://plone.org/security/hotfixes" = href=3D"https://plone.org/hotfixes" data-linktype=3D"external" = style=3D"color: rgb(65, 110, 210); max-width: 100%;" class=3D"">current = vulnerability list</a> and the <a = href=3D"https://old.plone.org/products/plone/security/" style=3D"color: = rgb(65, 110, 210); max-width: 100%;" class=3D"">old vulnerability = list</a></p></div></div></div></blockquote></div></body></html>= --Apple-Mail=_ACD08F36-4BD1-44BA-9414-F6CEC3AFEE49-- --===============7517648016273322372== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, SlashDot.org! http://sdm.link/slashdot --===============7517648016273322372== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Want community news? Subscribe to our newsletter http://eepurl.com/S4wfL Plone-Announce mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/plone-announce --===============7517648016273322372==--