Volto security advisory 20251001
"Important Announcements, Plone releases, and security-related notifications. Recommended subscription for all Plone developers and site admins" <[email protected]> Wed, 1 Oct 2025 14:20:21 +0200
| Newsgroups | gmane.comp.web.zope.plone.announce |
|---|---|
| Message-ID | <mailman.30559.1759328410.1583.plone-announce@lists.sourceforge.net> |
This is a multi-part message in MIME format.
--===============6957856767396619598==
Content-Type: multipart/alternative;
boundary="------------amr2W0bGGsNBUeZbPXzh2P45"
Content-Language: en-GB
This is a multi-part message in MIME format.
--------------amr2W0bGGsNBUeZbPXzh2P45
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
On behalf of the Plone Zope Security Team and the Volto team, we
announce security releases for Volto, due to the following vulnerability:
Impact
When visiting a specific URL, an anonymous user could cause the NodeJS
server part of Volto to quit with an error.
Patches
The problem has been patched and the patch has been backported to Volto
major versions down until 16. It is advised to upgrade to the latest
patch release of your respective current major version:
* Volto 16: 16.34.1, https://github.com/plone/volto/releases/tag/16.34.1
* Volto 17: 17.22.2, https://github.com/plone/volto/releases/tag/17.22.2
* Volto 18: 18.27.2, https://github.com/plone/volto/releases/tag/18.27.2
* Volto 19: 19.0.0-alpha6,
https://github.com/plone/volto/releases/tag/19.0.0-alpha.6
Workarounds
Make sure your setup automatically restarts processes that quit with an
error. This won't prevent a crash, but it minimises downtime.
Report
The problem was discovered by FHNW, a client of Plone provider
kitconcept, who shared it with the Plone Zope Security Team
(security-z4DKO/[email protected]).
Github Advisory
The same information was published to GitHub in this advisory:
https://github.com/plone/volto/security/advisories/GHSA-m8rj-ppph-mj33.
Text copied from plone.org advisory:
https://plone.org/security/announcements/plone-security-advisory-20251001.
Maurits van Rees
Plone Zope Security Team
--------------amr2W0bGGsNBUeZbPXzh2P45
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
</head>
<body>
<p> </p>
<div class="moz-text-html" lang="x-unicode">
<p>On behalf of the Plone Zope Security Team and the Volto team,
we announce security releases for Volto, due to the following
vulnerability:</p>
<h2>Impact</h2>
<p>When visiting a specific URL, an anonymous user could cause the
NodeJS server part of Volto to quit with an error.</p>
<h2>Patches</h2>
<p>The problem has been patched and the patch has been backported
to Volto major versions down until 16. It is advised to upgrade
to the latest patch release of your respective current major
version:</p>
<ul>
<li>Volto 16: 16.34.1, <a class="moz-txt-link-freetext"
href="https://github.com/plone/volto/releases/tag/16.34.1">https://github.com/plone/volto/releases/tag/16.34.1</a></li>
<li>Volto 17: 17.22.2, <a class="moz-txt-link-freetext"
href="https://github.com/plone/volto/releases/tag/17.22.2">https://github.com/plone/volto/releases/tag/17.22.2</a></li>
<li>Volto 18: 18.27.2, <a class="moz-txt-link-freetext"
href="https://github.com/plone/volto/releases/tag/18.27.2">https://github.com/plone/volto/releases/tag/18.27.2</a></li>
<li>Volto 19: 19.0.0-alpha6, <a class="moz-txt-link-freetext"
href="https://github.com/plone/volto/releases/tag/19.0.0-alpha.6">https://github.com/plone/volto/releases/tag/19.0.0-alpha.6</a></li>
</ul>
<p></p>
<h2>Workarounds</h2>
<p>Make sure your setup automatically restarts processes that quit
with an error. This won't prevent a crash, but it minimises
downtime.</p>
<h2>Report</h2>
<p>The problem was discovered by FHNW, a client of Plone provider
kitconcept, who shared it with the Plone Zope Security Team (<a
class="moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:security-z4DKO/[email protected]">security-z4DKO/[email protected]</a>).</p>
<h2>Github Advisory</h2>
<p>The same information was published to GitHub in this advisory:
<a class="moz-txt-link-freetext"
href="https://github.com/plone/volto/security/advisories/GHSA-m8rj-ppph-mj33">https://github.com/plone/volto/security/advisories/GHSA-m8rj-ppph-mj33</a>.</p>
<p>Text copied from plone.org advisory:
<a class="moz-txt-link-freetext"
href="https://plone.org/security/announcements/plone-security-advisory-20251001">https://plone.org/security/announcements/plone-security-advisory-20251001</a>.<br>
<br>
</p>
<p>Maurits van Rees<br>
Plone Zope Security Team<br>
<br>
</p>
</div>
<p><br>
</p>
</body>
</html>
--------------amr2W0bGGsNBUeZbPXzh2P45--
--===============6957856767396619598==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============6957856767396619598==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Plone-Announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-announce
--===============6957856767396619598==--