Security patch 20210518 version 1.5 released — Plone: Enterprise Level CMS - Free and Ope nSource - Community Driven - Secure
"Important Announcements, Plone releases, and security-related notifications. Recommended subscription for all Plone developers and site admins" <[email protected]> Thu, 1 Jul 2021 15:06:45 -0500
| Newsgroups | gmane.comp.web.zope.plone.announce |
|---|---|
| Message-ID | <mailman.84491.1625170037.1299.plone-announce@lists.sourceforge.net> |
--===============8773127584922360596==
Content-Type: multipart/alternative;
boundary="Apple-Mail=_738623D5-029A-43D0-B4BE-D4F988DF716A"
--Apple-Mail=_738623D5-029A-43D0-B4BE-D4F988DF716A
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
charset=utf-8
>=20
> =
https://plone.org/news/2021/security-patch-20210518-version-1-5-released =
<https://plone.org/news/2021/security-patch-20210518-version-1-5-released>=
>=20
> Security patch 20210518 version 1.5 released
>=20
> Version 1.5 of the hotfix to patch various vulnerabilities. This =
hotfix is recommended for Plone 4.3, 5.0, 5.1 and 5.2.
>=20
> This is a routine patch. There is no evidence that the issues fixed =
here are being used against any sites.
>=20
> Version 1.5 of the hotfix is available from:
>=20
> https://plone.org/security/hotfix/20210518 =
<https://plone.org/security/hotfix/20210518> =E2=80=93 if you grab the =
zip from here, please check that the version.txt contains 1.5 and/or =
that the md5/sha sum matches. You may get an older version from the =
cache. Try adding ?x=3D1 to the URL if this happens.
> https://pypi.org/project/Products.PloneHotfix20210518/ =
<https://pypi.org/project/Products.PloneHotfix20210518/>
> This version is a recommended upgrade for all users.
>=20
> Zope users are advised to upgrade to Zope 4.6.1 or 5.2.1. If this is =
not possible, you can try this new version of the hotfix.
>=20
> See the original 20210518 hotfix announcement =
<https://plone.org/security/announcements/security-patch-released-20210518=
>
> =46rom the changelog:
>=20
> 1.5 (2021-06-28)
>=20
> Fixed new XSS vulnerability in folder contents on Plone 5.0 and =
higher.
> Added support for environment variable STRICT_TRAVERSE_CHECK.
> Default value is 0, which means as strict as the code from version =
1.4.
> Value 1 is very strict, the same as the stricter code introduced in =
Zope 5.2.1 and now taken over in Zope 4.6.2. There are known issues in =
Plone with this, for example in the versions history view.
> Value 2 means: try to be strict, but if this fails we show a warning =
and return the found object anyway. The idea would be to use this in =
development or production for a while, to see which code needs a fix.
> Fix Remote Code Execution via traversal in expressions via string =
formatter. This is a variant of two earlier vulnerabilities in this =
hotfix. This was fixed in Zope 4.6.2, which takes over the already =
stricter code from Zope 5.2.1.
> Note: we don't usually release another version almost six weeks after =
the original one, and three weeks after the previous version, and =
including a fix for a vulnerability which was only reported last week. =
However, this contains a fix for a close variant of one of the original =
vulnerabilities and needs a fix in the same code, so it seemed easiest =
for the security team and for Plone users who patch their sites to =
release a newer version.
--Apple-Mail=_738623D5-029A-43D0-B4BE-D4F988DF716A
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
charset=utf-8
<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"><base></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D""><base=
class=3D""><div class=3D"Apple-Mail-URLShareUserContentTopClass"><br =
class=3D""></div><div =
class=3D"Apple-Mail-URLShareWrapperClass"><blockquote type=3D"cite" =
style=3D"border-left-style: none; color: inherit; padding: inherit; =
margin: inherit;" class=3D""><div class=3D""><div =
class=3D"original-url"><br class=3D""><a =
href=3D"https://plone.org/news/2021/security-patch-20210518-version-1-5-re=
leased" =
class=3D"">https://plone.org/news/2021/security-patch-20210518-version-1-5=
-released</a><br class=3D""><br class=3D""></div><div id=3D"article" =
role=3D"article" style=3D"text-rendering: optimizeLegibility; =
font-family: -apple-system-font; font-size: 1.2em; line-height: 1.5em; =
margin: 0px; padding: 0px;" class=3D"system exported">
<!-- This node will contain a number of div.page. -->
<div class=3D"page" style=3D"word-wrap: break-word; max-width: =
100%;"><h1 class=3D"title" style=3D"font-size: 1.95552em; line-height: =
1.2141em; margin-top: 0px; margin-bottom: 0.5em; max-width: =
100%;">Security patch 20210518 version 1.5 released</h1><h2 =
class=3D"subhead" style=3D"font-weight: normal; color: rgba(27, 27, 27, =
0.65); font-size: 1.46664em; margin-top: -0.35em; line-height: =
1.27275em; max-width: 100%;">Version 1.5 of the hotfix to patch various =
vulnerabilities. This hotfix is recommended for Plone 4.3, 5.0, 5.1 and =
5.2.</h2><p style=3D"max-width: 100%;" class=3D"">This is a routine =
patch. There is no evidence that the issues fixed here are being used =
against any sites.</p><p style=3D"max-width: 100%;" class=3D"">Version =
1.5 of the hotfix is available from:</p>
<ul style=3D"max-width: 100%;" class=3D"">
<li style=3D"max-width: 100%;" class=3D""><a =
href=3D"https://plone.org/security/hotfix/20210518" style=3D"color: =
rgb(65, 110, 210); max-width: 100%;" =
class=3D"">https://plone.org/security/hotfix/20210518</a> =E2=80=93 if =
you grab the zip from here, please check that the version.txt contains =
1.5 and/or that the md5/sha sum matches. You may get an older version =
from the cache. Try adding ?x=3D1 to the URL if this happens.</li>
<li style=3D"max-width: 100%;" class=3D""><a =
href=3D"https://pypi.org/project/Products.PloneHotfix20210518/" =
style=3D"color: rgb(65, 110, 210); max-width: 100%;" =
class=3D"">https://pypi.org/project/Products.PloneHotfix20210518/</a></li>=
</ul><p style=3D"max-width: 100%;" class=3D"">This version is a =
recommended upgrade for all users.</p><p style=3D"max-width: 100%;" =
class=3D"">Zope users are advised to upgrade to Zope 4.6.1 or =
5.2.1. If this is not possible, you can try this new version of the =
hotfix.</p><p style=3D"max-width: 100%;" class=3D"">See the original <a =
href=3D"https://plone.org/security/announcements/security-patch-released-2=
0210518" style=3D"color: rgb(65, 110, 210); max-width: 100%;" =
class=3D"">20210518 hotfix announcement</a></p><p style=3D"max-width: =
100%;" class=3D"">=46rom the changelog:</p>
<h3 style=3D"font-size: 1.25em; max-width: 100%;" class=3D"">1.5 =
(2021-06-28)</h3>
<ul style=3D"max-width: 100%;" class=3D"">
<li style=3D"max-width: 100%;" class=3D"">Fixed new XSS vulnerability in =
folder contents on Plone 5.0 and higher.</li>
<li style=3D"max-width: 100%;" class=3D"">Added support for environment =
variable STRICT_TRAVERSE_CHECK.
<ul style=3D"max-width: 100%;" class=3D"">
<li style=3D"max-width: 100%;" class=3D"">Default value is 0, which =
means as strict as the code from version 1.4.</li>
<li style=3D"max-width: 100%;" class=3D"">Value 1 is very strict, the =
same as the stricter code introduced in Zope 5.2.1 and now taken over in =
Zope 4.6.2. There are known issues in Plone with this, for example in =
the versions history view.</li>
<li style=3D"max-width: 100%;" class=3D"">Value 2 means: try to be =
strict, but if this fails we show a warning and return the found object =
anyway. The idea would be to use this in development or production for a =
while, to see which code needs a fix.</li>
</ul>
</li>
<li style=3D"max-width: 100%;" class=3D"">Fix Remote Code Execution via =
traversal in expressions via string formatter. This is a variant of two =
earlier vulnerabilities in this hotfix. This was fixed in Zope 4.6.2, =
which takes over the already stricter code from Zope 5.2.1.</li>
</ul><p style=3D"max-width: 100%;" class=3D"">Note: we don't usually =
release another version almost six weeks after the original one, and =
three weeks after the previous version, and including a fix for a =
vulnerability which was only reported last week. However, this contains =
a fix for a close variant of one of the original vulnerabilities and =
needs a fix in the same code, so it seemed easiest for the security team =
and for Plone users who patch their sites to release a newer =
version.</p></div></div></div></blockquote></div></body></html>=
--Apple-Mail=_738623D5-029A-43D0-B4BE-D4F988DF716A--
--===============8773127584922360596==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============8773127584922360596==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Plone-Announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-announce
--===============8773127584922360596==--