Re: Security vulnerability pre-announceme nt: 20200121 — Plone: Enterprise Level CMS - Free a nd OpenSource - Community Driven - Secure
"Announcement of Plone releases and security-related notifications. Recommended subscription for all Plone developers and site admins." <[email protected]> Mon, 20 Jan 2020 08:25:16 -0600
| Newsgroups | gmane.comp.web.zope.plone.announce |
|---|---|
| Message-ID | <mailman.29171.1579530899.2125.plone-announce@lists.sourceforge.net> |
--===============1112151025772835825==
Content-Type: multipart/alternative;
boundary="Apple-Mail=_784D091F-447E-4B3F-B7D5-D2CF292C5AD2"
--Apple-Mail=_784D091F-447E-4B3F-B7D5-D2CF292C5AD2
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
charset=utf-8
A reminder that tomorrow (Tuesday, January 21, 2020, 15:00 UTC) the =
hotfix will be released.
Please check your local time:
=
https://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2020&mo=3D1&d=
=3D21&h=3D15&mn=3D0=20
Q: Will Plone 5.2.1 also require the hotfix?
A: Yes, it will.
Kim=20
> On Jan 7, 2020, at 10:44 PM, T. Kim Nguyen <nguyen-z4DKO/[email protected]> wrote:
>=20
>=20
>>=20
>> https://plone.org/security/announcements/20200121-preannounce =
<https://plone.org/security/announcements/20200121-preannounce>
>>=20
>> Security vulnerability pre-announcement: 20200121
>>=20
>> Hotfix to patch various vulnerabilities
>>=20
>> This is a routine patch with our standard 14 day notice period. There =
is no evidence that the issues fixed here are being used against any =
sites.
>>=20
>> CVE numbers not yet issued.
>>=20
>> Versions Affected: All supported Plone versions (4.x, 5.x). Previous =
versions could be affected but have not been tested.
>>=20
>> Versions Not Affected: None.
>>=20
>> Nature of vulnerability: Low severity, no data exposure or privilege =
escalation for anonymous users.
>>=20
>> The patch will be released at 2020-01-21 15:00 UTC =
<http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2020&mo=3D01&=
d=3D21&h=3D15&mn=3D0>.
>>=20
>> Preparation
>>=20
>> This is a pre-announcement of availability of this security fix.=20
>>=20
>> The security fix egg will be named Products.PloneHotfix20200121 and =
its version will be 1.0. Further installation instructions will be made =
available when the fix is released.
>>=20
>> Standard security advice
>>=20
>> Make sure that the Zope/Plone service is running with minimum =
privileges. Ideally, the Zope and ZEO services should be able to write =
only to log and data directories. Plone sites installed through our =
installers already do this.
>> Use an intrusion detection system that monitors key system resources =
for unauthorized changes.
>> Monitor your Zope, reverse-proxy request and system logs for unusual =
activity.
>> Make sure your administrator stays up to date, by following the =
special low-volume Plone Security Announcements list via email =
<https://lists.sourceforge.net/lists/listinfo/plone-announce>, RSS =
<https://plone.org/security/announcements/RSS>and/or Twitter =
<https://twitter.com/plone>
>> These are standard precautions that should be employed on any =
production system, and are not tied to this fix.
>>=20
>> Extra Help
>>=20
>> Should you not have in-house server administrators or a service =
agreement for supporting your website, you can find consulting companies =
at plone.com/providers <http://plone.com/providers>
>> There is also free support=C2=A0 <https://plone.org/support>available =
online via the Plone forum <https://community.plone.org/> and the Plone =
chat=C2=A0channels <https://plone.org/support/chat>.
>>=20
>> Q: When will the patch be made available?
>> A: The Plone Security Team will release the patch at 2020-01-21 15:00 =
UTC =
<http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2020&mo=3D01&=
d=3D21&h=3D15&mn=3D0>.
>>=20
>> Q. What will be involved in applying the patch?
>> A. Patches are made available as tarball-style archives that may be =
unpacked into the products folder of a buildout installation and as =
Python packages that may be installed by editing a buildout =
configuration file and running buildout. Patching is generally easy and =
quick to accomplish.
>>=20
>> Q: How were these vulnerabilities found?
>> A: The vulnerabilities were found by users submitting them to the =
security mailing list.
>>=20
>> Q: My site is highly visible and mission-critical. I hear the patch =
has already been developed. Can I get the fix before the release date?
>> A: No. The patch will be made available to all administrators at the =
same time. There are no exceptions.
>>=20
>> Q: If the patch has been developed already, why isn't it made =
available to the public now?
>> A: The Security Team is still testing the patch against a wide =
variety of configurations and running various scenarios thoroughly. The =
team is also making sure everybody has appropriate time to plan to patch =
their Plone installation(s). Some consultancy organizations have =
hundreds of sites to patch and need the extra time to coordinate their =
efforts with their clients.
>>=20
>> Q: How does one exploit the vulnerability?
>> A: This information will not be made public until after the patch is =
made available.
>>=20
>> Q: Is my Plone site at risk for this vulnerability? How do I know if =
my site has been exploited? How can I confirm that the hotfix is =
installed correctly and my site is protected?
>>=20
>> A: Details about the vulnerability will be revealed at the same time =
as the patch.
>>=20
>> Q: How can I report other potential security vulnerabilities?
>>=20
>> A: Please email the Plone Security Team at security-z4DKO/[email protected] =
<mailto:security-z4DKO/[email protected]> rather than publicly discussing potential =
security issues.
>>=20
>> Q: How can I apply the patch without affecting my users?
>>=20
>> A: Even though this patch does NOT require you to run buildout, you =
can run buildout without affecting your users. You can restart a =
multi-client Plone install without affecting your users; see =
http://docs.plone.org/manage/deploying/processes.html =
<http://docs.plone.org/manage/deploying/processes.html> =20
>>=20
>> Q: How do I get help patching my site?
>>=20
>> A: Plone service providers are listed at plone.com/providers =
<http://plone.com/providers> There is also free support=C2=A0 =
<https://plone.org/support>available online via the Plone=C2=A0forum =
<https://community.plone.org/> and the Plone chat=C2=A0channels =
<https://plone.org/support/chat>
>> Q: Who is on the Plone Security Team and how is it funded?
>>=20
>> A: The Plone Security Team <https://plone.org/community/security> is =
made up of volunteers who are experienced developers familiar with the =
Plone code base and with security exploits. The Plone Security Team is =
not funded; members and/or their employers have volunteered their time =
in the interests of the greater Plone community.
>>=20
>> Q: How can I help the Plone Security Team?
>>=20
>> A: The Plone Security Team is looking for help from security-minded =
developers and testers. Volunteers must be known to the Security Team =
and have been part of the Plone community for some time. To help the =
Security Team financially, your donations are most welcome at =
http://plone.org/sponsors <https://plone.org/sponsors>
>> General questions about this announcement, Plone patching procedures, =
and availability of support may be addressed to the Plone support forums =
<https://plone.org/support> If you have specific questions about this =
vulnerability or its handling, contact the Plone Security Team at =
security-z4DKO/[email protected] <mailto:security-z4DKO/[email protected]>
>> To report potentially security-related issues, email the Plone =
Security Team at security-z4DKO/[email protected] <mailto:security-z4DKO/[email protected]> We are =
always happy to credit individuals and companies who make responsible =
disclosures.
>>=20
>> Information for Vulnerability Database Maintainers
>>=20
>> We will apply for CVE numbers for these issues. Further information =
on individual vulnerabilities (including CVSS scores, CWE identifiers =
and summaries) will be available at the full vulnerability list. =
<https://plone.org/hotfixes>
--Apple-Mail=_784D091F-447E-4B3F-B7D5-D2CF292C5AD2
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
charset=us-ascii
<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dus-ascii"><base></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D"">A =
reminder that tomorrow (Tuesday, January 21, 2020, 15:00 UTC) the hotfix =
will be released.<br class=3D""><br class=3D"">Please check your local =
time:<br class=3D""><br class=3D""><a =
href=3D"https://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2020&=
amp;mo=3D1&d=3D21&h=3D15&mn=3D0" =
class=3D"">https://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D20=
20&mo=3D1&d=3D21&h=3D15&mn=3D0</a> <div =
class=3D""><br class=3D""></div><div class=3D"">Q: Will Plone 5.2.1 =
also require the hotfix?<br class=3D"">A: Yes, it will.</div><div =
class=3D""><br class=3D""></div><div class=3D""> =
Kim <br class=3D""><div><br class=3D""><blockquote type=3D"cite" =
class=3D""><div class=3D"">On Jan 7, 2020, at 10:44 PM, T. Kim Nguyen =
<<a href=3D"mailto:nguyen-z4DKO/[email protected]" =
class=3D"">nguyen-z4DKO/[email protected]</a>> wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><meta =
http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii" =
class=3D""><base class=3D""><div style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D""><base=
class=3D""><div class=3D"Apple-Mail-URLShareUserContentTopClass"><br =
class=3D""></div><div =
class=3D"Apple-Mail-URLShareWrapperClass"><blockquote type=3D"cite" =
style=3D"border-left-style: none; color: inherit; padding: inherit; =
margin: inherit;" class=3D""><div class=3D""><div =
class=3D"original-url"><br class=3D""><a =
href=3D"https://plone.org/security/announcements/20200121-preannounce" =
class=3D"">https://plone.org/security/announcements/20200121-preannounce</=
a><br class=3D""><br class=3D""></div><div id=3D"article" role=3D"article"=
style=3D"text-rendering: optimizeLegibility; font-family: =
-apple-system-font; font-size: 1.2em; line-height: 1.5em; margin: 0px; =
padding: 0px;" class=3D"system exported">
<!-- This node will contain a number of div.page. -->
<div class=3D"page" style=3D"word-wrap: break-word; max-width: =
100%;"><h1 class=3D"title" style=3D"font-size: 1.95552em; line-height: =
1.2141em; margin-top: 0px; margin-bottom: 0.5em; max-width: =
100%;">Security vulnerability pre-announcement: 20200121</h1><h2 =
class=3D"subhead" style=3D"font-weight: normal; color: rgba(27, 27, 27, =
0.65098); font-size: 1.46664em; margin-top: -0.35em; line-height: =
1.27275em; max-width: 100%;">Hotfix to patch various =
vulnerabilities</h2><p style=3D"max-width: 100%;" class=3D""><em =
style=3D"max-width: 100%;" class=3D"">This is a routine patch with our =
standard 14 day notice period. There is no evidence that the issues =
fixed here are being used against any sites.</em></p><p =
style=3D"max-width: 100%;" class=3D"">CVE numbers not yet issued.</p><p =
style=3D"max-width: 100%;" class=3D""><strong style=3D"max-width: 100%;" =
class=3D"">Versions Affected:</strong> All supported Plone versions =
(4.x, 5.x). Previous versions could be affected but have not been =
tested.</p><p style=3D"max-width: 100%;" class=3D""><strong =
style=3D"max-width: 100%;" class=3D"">Versions Not Affected:</strong> =
None.</p><p style=3D"max-width: 100%;" class=3D""><strong =
style=3D"max-width: 100%;" class=3D"">Nature of =
vulnerability:</strong> Low severity, no data exposure or privilege =
escalation for anonymous users.</p><p style=3D"max-width: 100%;" =
class=3D""><strong style=3D"max-width: 100%;" class=3D"">The patch will =
be released at <a target=3D"_blank" =
href=3D"http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2020&a=
mp;mo=3D01&d=3D21&h=3D15&mn=3D0" rel=3D"noopener" =
style=3D"color: rgb(65, 110, 210); max-width: 100%;" class=3D"">2020-01-21=
15:00 UTC</a>.</strong></p>
<h2 style=3D"font-size: 1.43em; max-width: 100%;" =
class=3D"">Preparation</h2><p style=3D"max-width: 100%;" class=3D"">This =
is a pre-announcement of availability of this security fix. </p><p =
style=3D"max-width: 100%;" class=3D"">The security fix egg will be =
named <code style=3D"max-width: 100%;" =
class=3D"">Products.PloneHotfix20200121</code> and its version will be =
<code style=3D"max-width: 100%;" class=3D"">1.0</code>. Further =
installation instructions will be made available when the fix is =
released.</p>
<h3 style=3D"font-size: 1.25em; max-width: 100%;" class=3D"">Standard =
security advice</h3>
<ul style=3D"max-width: 100%;" class=3D"">
<li style=3D"max-width: 100%;" class=3D"">Make sure that the Zope/Plone =
service is running with minimum privileges. Ideally, the Zope and ZEO =
services should be able to write only to log and data directories. Plone =
sites installed through our installers already do this.</li>
<li style=3D"max-width: 100%;" class=3D"">Use an intrusion detection =
system that monitors key system resources for unauthorized changes.</li>
<li style=3D"max-width: 100%;" class=3D"">Monitor your Zope, =
reverse-proxy request and system logs for unusual activity.</li>
<li style=3D"max-width: 100%;" class=3D"">Make sure your administrator =
stays up to date, by following the special low-volume <a title=3D"" =
href=3D"https://lists.sourceforge.net/lists/listinfo/plone-announce" =
target=3D"_self" style=3D"color: rgb(65, 110, 210); max-width: 100%;" =
class=3D"">Plone Security Announcements list via email</a>, <a =
href=3D"https://plone.org/security/announcements/RSS" style=3D"color: =
rgb(65, 110, 210); max-width: 100%;" class=3D"">RSS </a>and/or <a =
title=3D"" href=3D"https://twitter.com/plone" target=3D"_self" =
style=3D"color: rgb(65, 110, 210); max-width: 100%;" =
class=3D"">Twitter</a></li>
</ul><p style=3D"max-width: 100%;" class=3D"">These are standard =
precautions that should be employed on any production system, and are =
not tied to this fix.</p>
<h3 style=3D"font-size: 1.25em; max-width: 100%;" class=3D"">Extra =
Help</h3><p style=3D"max-width: 100%;" class=3D"">Should you not have =
in-house server administrators or a service agreement for supporting =
your website, you can find consulting companies at <a =
href=3D"http://plone.com/providers" style=3D"color: rgb(65, 110, 210); =
max-width: 100%;" class=3D"">plone.com/providers</a></p><p =
style=3D"max-width: 100%;" class=3D"">There is also <a =
href=3D"https://plone.org/support" style=3D"color: rgb(65, 110, 210); =
max-width: 100%;" class=3D"">free support </a>available online via =
the <a href=3D"https://community.plone.org/" style=3D"color: rgb(65, =
110, 210); max-width: 100%;" class=3D"">Plone forum</a> and the <a =
href=3D"https://plone.org/support/chat" style=3D"color: rgb(65, 110, =
210); max-width: 100%;" class=3D"">Plone chat channels</a>.</p><p =
style=3D"max-width: 100%;" class=3D""><strong style=3D"max-width: 100%;" =
class=3D"">Q: When will the patch be made available?<br =
style=3D"max-width: 100%;" class=3D""></strong>A: The Plone Security =
Team will release the patch at <a =
href=3D"http://www.worldtimeserver.com/convert_time_in_UTC.aspx?y=3D2020&a=
mp;mo=3D01&d=3D21&h=3D15&mn=3D0" style=3D"color: rgb(65, =
110, 210); max-width: 100%;" class=3D"">2020-01-21 15:00 UTC</a>.</p><p =
style=3D"max-width: 100%;" class=3D""><strong style=3D"max-width: 100%;" =
class=3D"">Q. What will be involved in applying the patch?<br =
style=3D"max-width: 100%;" class=3D""></strong>A. Patches are made =
available as tarball-style archives that may be unpacked into the <kbd =
style=3D"max-width: 100%;" class=3D"">products</kbd> folder of a =
buildout installation and as Python packages that may be installed by =
editing a buildout configuration file and running buildout. Patching is =
generally easy and quick to accomplish.</p><p style=3D"max-width: 100%;" =
class=3D""><strong style=3D"max-width: 100%;" class=3D"">Q: How were =
these vulnerabilities found?<br style=3D"max-width: 100%;" =
class=3D""></strong>A: The vulnerabilities were found by users =
submitting them to the security mailing list.</p><p style=3D"max-width: =
100%;" class=3D""><strong style=3D"max-width: 100%;" class=3D"">Q: My =
site is highly visible and mission-critical. I hear the patch has =
already been developed. Can I get the fix before the release =
date?</strong><br style=3D"max-width: 100%;" class=3D"">A: No. The patch =
will be made available to <strong style=3D"max-width: 100%;" =
class=3D"">all administrators at the same time</strong>. There are no =
exceptions.</p><p style=3D"max-width: 100%;" class=3D""><strong =
style=3D"max-width: 100%;" class=3D"">Q: If the patch has been developed =
already, why isn't it made available to the public now?<br =
style=3D"max-width: 100%;" class=3D""></strong> A: The Security Team is =
still testing the patch against a wide variety of configurations and =
running various scenarios thoroughly. The team is also making sure =
everybody has appropriate time to plan to patch their Plone =
installation(s). Some consultancy organizations have hundreds of sites =
to patch and need the extra time to coordinate their efforts with their =
clients.</p><p style=3D"max-width: 100%;" class=3D""><strong =
style=3D"max-width: 100%;" class=3D"">Q: How does one exploit the =
vulnerability?<br style=3D"max-width: 100%;" class=3D""></strong>A: This =
information will not be made public until after the patch is made =
available.</p><p style=3D"max-width: 100%;" class=3D""><strong =
style=3D"max-width: 100%;" class=3D"">Q: Is my Plone site at risk for =
this vulnerability?</strong><strong style=3D"max-width: 100%;" =
class=3D""> How do I know if my site has been =
exploited?</strong><strong style=3D"max-width: 100%;" class=3D""> How=
can I confirm that the hotfix is installed correctly and my site is =
protected?</strong></p><p style=3D"max-width: 100%;" class=3D"">A: =
Details about the vulnerability will be revealed at the same time as the =
patch.</p><p style=3D"max-width: 100%;" class=3D""><strong =
style=3D"max-width: 100%;" class=3D"">Q: How can I report other =
potential security vulnerabilities?</strong></p><p style=3D"max-width: =
100%;" class=3D"">A: Please email the Plone Security Team at <a =
href=3D"mailto:security-z4DKO/[email protected]" style=3D"color: rgb(65, 110, 210); =
max-width: 100%;" class=3D"">security-z4DKO/[email protected]</a> rather than =
publicly discussing potential security issues.</p><p style=3D"max-width: =
100%;" class=3D""><strong style=3D"max-width: 100%;" class=3D"">Q: How =
can I apply the patch without affecting my users?</strong></p><p =
style=3D"max-width: 100%;" class=3D"">A: Even though this patch does NOT =
require you to run buildout, you can run buildout without affecting your =
users. You can restart a multi-client Plone install without affecting =
your users; see <a =
href=3D"http://docs.plone.org/manage/deploying/processes.html" =
style=3D"color: rgb(65, 110, 210); max-width: 100%;" =
class=3D"">http://docs.plone.org/manage/deploying/processes.html</a> =
</p><p style=3D"max-width: 100%;" class=3D""><strong =
style=3D"max-width: 100%;" class=3D"">Q: How do I get help patching my =
site?</strong></p><p style=3D"max-width: 100%;" class=3D"">A: Plone =
service providers are listed at <a =
href=3D"http://plone.com/providers" style=3D"color: rgb(65, 110, 210); =
max-width: 100%;" class=3D"">plone.com/providers</a> There is =
also <a href=3D"https://plone.org/support" style=3D"color: rgb(65, =
110, 210); max-width: 100%;" class=3D"">free support </a>available =
online via the <a href=3D"https://community.plone.org/" style=3D"color: =
rgb(65, 110, 210); max-width: 100%;" =
class=3D"">Plone forum</a> and the <a =
href=3D"https://plone.org/support/chat" style=3D"color: rgb(65, 110, =
210); max-width: 100%;" class=3D"">Plone chat channels</a></p><p =
style=3D"max-width: 100%;" class=3D""><strong style=3D"max-width: 100%;" =
class=3D"">Q: Who is on the Plone Security Team and how is it =
funded?</strong></p><p style=3D"max-width: 100%;" class=3D"">A: The <a =
href=3D"https://plone.org/community/security" style=3D"color: rgb(65, =
110, 210); max-width: 100%;" class=3D"">Plone Security Team</a> is made =
up of volunteers who are experienced developers familiar with the Plone =
code base and with security exploits. The Plone Security Team is not =
funded; members and/or their employers have volunteered their time in =
the interests of the greater Plone community.</p><p style=3D"max-width: =
100%;" class=3D""><strong style=3D"max-width: 100%;" class=3D"">Q: How =
can I help the Plone Security Team?</strong></p><p style=3D"max-width: =
100%;" class=3D"">A: The Plone Security Team is looking for help =
from security-minded developers and testers. Volunteers must be =
known to the Security Team and have been part of the Plone community for =
some time. To help the Security Team financially, your donations are =
most welcome at <a target=3D"_blank" href=3D"https://plone.org/sponsors" =
rel=3D"noopener" style=3D"color: rgb(65, 110, 210); max-width: 100%;" =
class=3D"">http://plone.org/sponsors</a></p><p style=3D"max-width: =
100%;" class=3D""><strong style=3D"max-width: 100%;" class=3D"">General =
questions about this announcement</strong>, Plone patching procedures, =
and availability of support may be addressed to the <a =
href=3D"https://plone.org/support" style=3D"color: rgb(65, 110, 210); =
max-width: 100%;" class=3D"">Plone support forums</a> If you =
have specific questions about this vulnerability or its =
handling, contact the Plone Security Team at <a =
href=3D"mailto:security-z4DKO/[email protected]" style=3D"color: rgb(65, 110, 210); =
max-width: 100%;" class=3D"">security-z4DKO/[email protected]</a></p><p =
style=3D"max-width: 100%;" class=3D""><strong style=3D"max-width: 100%;" =
class=3D"">To report potentially security-related =
issues</strong>, email the Plone Security Team at <a =
href=3D"mailto:security-z4DKO/[email protected]" style=3D"color: rgb(65, 110, 210); =
max-width: 100%;" class=3D"">security-z4DKO/[email protected]</a> We are always =
happy to credit individuals and companies who make responsible =
disclosures.</p>
<h3 style=3D"font-size: 1.25em; max-width: 100%;" class=3D"">Information =
for Vulnerability Database Maintainers</h3><p style=3D"max-width: 100%;" =
class=3D"">We will apply for CVE numbers for these issues. Further =
information on individual vulnerabilities (including CVSS scores, CWE =
identifiers and summaries) will be available at <a =
href=3D"https://plone.org/hotfixes" style=3D"color: rgb(65, 110, 210); =
max-width: 100%;" class=3D"">the full vulnerability =
list.</a></p></div></div></div></blockquote></div></div></div></blockquote=
></div><br class=3D""></div></body></html>=
--Apple-Mail=_784D091F-447E-4B3F-B7D5-D2CF292C5AD2--
--===============1112151025772835825==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============1112151025772835825==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Want community news? Subscribe to our newsletter http://eepurl.com/S4wfL
Plone-Announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-announce
--===============1112151025772835825==--