Plone security advisory 20260302

"Important Announcements, Plone releases, and security-related notifications. Recommended subscription for all Plone developers and site admins" <[email protected]> Mon, 2 Mar 2026 15:22:04 +0100
Newsgroups gmane.comp.web.zope.plone.announce
Message-ID <mailman.161088.1772482451.8001.plone-announce@lists.sourceforge.net>
This is a multi-part message in MIME format.
--===============6995837535435700143==
Content-Type: multipart/alternative;
 boundary="------------ZR2uD3OusNi1E6zY9tTPwlsJ"
Content-Language: en-GB

This is a multi-part message in MIME format.
--------------ZR2uD3OusNi1E6zY9tTPwlsJ
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

This is a copy of an advisory published on GitHub today:
https://github.com/plone/Products.isurlinportal/security/advisories/GHSA-43gx-6gv6-3jcp

*Possible open redirect when using more than 2 forward slashes
*
*Impact*
A url `/login?came_from=////evil.example` may redirect to an external 
website after login.

Standard Plone is not affected, but if you have customised the login, 
for example with add-ons, you might be affected. You can try the url to 
check if you are affected or not.

*Patches*
The problem has been patched in `Products.isurlinportal`.

* Plone 6.2: upgrade to `Products.isurlinportal` 4.0.0.
* Plone 6.1: upgrade to `Products.isurlinportal` 3.1.0.
* Plone 6.0: upgrade to `Products.isurlinportal` 2.1.0.
* Older Plone versions don't have security support anymore.

*Workarounds*
There are no known workarounds.

*Background*
When you are anonymous and land on a page that requires a login, Plone 
sends you to the login form. After successful login, Plone redirects you 
back to the page you came from.  Various other forms and pages have a 
similar system.
This could get abused by an attacker to trick Plone into redirecting to 
a different website. Plone checks the page that would be redirected to. 
It is only accepted if it is within the Plone site domain or part of a 
different trusted domain.
The main check for this is in the `Products.isurlinportal` package. A 
lot of potentially malicious urls are already safely rejected, but here 
a loop hole was found.

This was discovered during a penetration test by the CERT-EU Team.

Thank you Alessandro Pisa for contacting me for the Plone Security Team 
and supplying a fix and tests.

Maurits van Rees
Plone/Zope Security Team



--------------ZR2uD3OusNi1E6zY9tTPwlsJ
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>This is a copy of an advisory published on GitHub today:<br>
<a class="moz-txt-link-freetext" href="https://github.com/plone/Products.isurlinportal/security/advisories/GHSA-43gx-6gv6-3jcp">https://github.com/plone/Products.isurlinportal/security/advisories/GHSA-43gx-6gv6-3jcp</a></p>
    <p><b>Possible open redirect when using more than 2 forward slashes<br>
      </b><br>
      <b>Impact</b><br>
      A url `/login?came_from=////evil.example` may redirect to an
      external website after login.<br>
      <br>
      Standard Plone is not affected, but if you have customised the
      login, for example with add-ons, you might be affected. You can
      try the url to check if you are affected or not.<br>
      <br>
      <b>Patches</b><br>
      The problem has been patched in `Products.isurlinportal`.<br>
      <br>
      * Plone 6.2: upgrade to `Products.isurlinportal` 4.0.0.<br>
      * Plone 6.1: upgrade to `Products.isurlinportal` 3.1.0.<br>
      * Plone 6.0: upgrade to `Products.isurlinportal` 2.1.0.<br>
      * Older Plone versions don't have security support anymore.<br>
      <br>
      <b>Workarounds</b><br>
      There are no known workarounds.<br>
      <br>
      <b>Background</b><br>
      When you are anonymous and land on a page that requires a login,
      Plone sends you to the login form. After successful login, Plone
      redirects you back to the page you came from.  Various other forms
      and pages have a similar system.<br>
      This could get abused by an attacker to trick Plone into
      redirecting to a different website. Plone checks the page that
      would be redirected to. It is only accepted if it is within the
      Plone site domain or part of a different trusted domain.<br>
      The main check for this is in the `Products.isurlinportal`
      package. A lot of potentially malicious urls are already safely
      rejected, but here a loop hole was found.<br>
      <br>
      This was discovered during a penetration test by the CERT-EU Team.</p>
    <p>Thank you Alessandro Pisa for contacting me for the Plone
      Security Team and supplying a fix and tests.</p>
    <p>Maurits van Rees<br>
      Plone/Zope Security Team</p>
    <p><br>
    </p>
    <p><br>
    </p>
  </body>
</html>

--------------ZR2uD3OusNi1E6zY9tTPwlsJ--


--===============6995837535435700143==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============6995837535435700143==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________

Plone-Announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-announce
--===============6995837535435700143==--