Volto security advisory 20251001

"Important Announcements, Plone releases, and security-related notifications. Recommended subscription for all Plone developers and site admins" <[email protected]> Wed, 1 Oct 2025 14:20:21 +0200
Newsgroups gmane.comp.web.zope.plone.announce
Message-ID <mailman.30559.1759328410.1583.plone-announce@lists.sourceforge.net>
This is a multi-part message in MIME format.
--===============6957856767396619598==
Content-Type: multipart/alternative;
 boundary="------------amr2W0bGGsNBUeZbPXzh2P45"
Content-Language: en-GB

This is a multi-part message in MIME format.
--------------amr2W0bGGsNBUeZbPXzh2P45
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit

On behalf of the Plone Zope Security Team and the Volto team, we 
announce security releases for Volto, due to the following vulnerability:


    Impact

When visiting a specific URL, an anonymous user could cause the NodeJS 
server part of Volto to quit with an error.


    Patches

The problem has been patched and the patch has been backported to Volto 
major versions down until 16. It is advised to upgrade to the latest 
patch release of your respective current major version:

  * Volto 16: 16.34.1, https://github.com/plone/volto/releases/tag/16.34.1
  * Volto 17: 17.22.2, https://github.com/plone/volto/releases/tag/17.22.2
  * Volto 18: 18.27.2, https://github.com/plone/volto/releases/tag/18.27.2
  * Volto 19: 19.0.0-alpha6,
    https://github.com/plone/volto/releases/tag/19.0.0-alpha.6


    Workarounds

Make sure your setup automatically restarts processes that quit with an 
error. This won't prevent a crash, but it minimises downtime.


    Report

The problem was discovered by FHNW, a client of Plone provider 
kitconcept, who shared it with the Plone Zope Security Team 
(security-z4DKO/[email protected]).


    Github Advisory

The same information was published to GitHub in this advisory: 
https://github.com/plone/volto/security/advisories/GHSA-m8rj-ppph-mj33.

Text copied from plone.org advisory: 
https://plone.org/security/announcements/plone-security-advisory-20251001.

Maurits van Rees
Plone Zope Security Team


--------------amr2W0bGGsNBUeZbPXzh2P45
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit

<!DOCTYPE html>
<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p> </p>
    <div class="moz-text-html" lang="x-unicode">
      <p>On behalf of the Plone Zope Security Team and the Volto team,
        we announce security releases for Volto, due to the following
        vulnerability:</p>
      <h2>Impact</h2>
      <p>When visiting a specific URL, an anonymous user could cause the
        NodeJS server part of Volto to quit with an error.</p>
      <h2>Patches</h2>
      <p>The problem has been patched and the patch has been backported
        to Volto major versions down until 16. It is advised to upgrade
        to the latest patch release of your respective current major
        version:</p>
      <ul>
        <li>Volto 16: 16.34.1, <a class="moz-txt-link-freetext"
            href="https://github.com/plone/volto/releases/tag/16.34.1">https://github.com/plone/volto/releases/tag/16.34.1</a></li>
        <li>Volto 17: 17.22.2, <a class="moz-txt-link-freetext"
            href="https://github.com/plone/volto/releases/tag/17.22.2">https://github.com/plone/volto/releases/tag/17.22.2</a></li>
        <li>Volto 18: 18.27.2, <a class="moz-txt-link-freetext"
            href="https://github.com/plone/volto/releases/tag/18.27.2">https://github.com/plone/volto/releases/tag/18.27.2</a></li>
        <li>Volto 19: 19.0.0-alpha6, <a class="moz-txt-link-freetext"
href="https://github.com/plone/volto/releases/tag/19.0.0-alpha.6">https://github.com/plone/volto/releases/tag/19.0.0-alpha.6</a></li>
      </ul>
      <p></p>
      <h2>Workarounds</h2>
      <p>Make sure your setup automatically restarts processes that quit
        with an error. This won't prevent a crash, but it minimises
        downtime.</p>
      <h2>Report</h2>
      <p>The problem was discovered by FHNW, a client of Plone provider
        kitconcept, who shared it with the Plone Zope Security Team (<a
          class="moz-txt-link-abbreviated moz-txt-link-freetext"
          href="mailto:security-z4DKO/[email protected]">security-z4DKO/[email protected]</a>).</p>
      <h2>Github Advisory</h2>
      <p>The same information was published to GitHub in this advisory:
        <a class="moz-txt-link-freetext"
href="https://github.com/plone/volto/security/advisories/GHSA-m8rj-ppph-mj33">https://github.com/plone/volto/security/advisories/GHSA-m8rj-ppph-mj33</a>.</p>
      <p>Text copied from plone.org advisory:
        <a class="moz-txt-link-freetext"
href="https://plone.org/security/announcements/plone-security-advisory-20251001">https://plone.org/security/announcements/plone-security-advisory-20251001</a>.<br>
        <br>
      </p>
      <p>Maurits van Rees<br>
        Plone Zope Security Team<br>
        <br>
      </p>
    </div>
    <p><br>
    </p>
  </body>
</html>

--------------amr2W0bGGsNBUeZbPXzh2P45--


--===============6957856767396619598==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============6957856767396619598==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________

Plone-Announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-announce
--===============6957856767396619598==--