Plone security advisory 20260302
"Important Announcements, Plone releases, and security-related notifications. Recommended subscription for all Plone developers and site admins" <[email protected]> Mon, 2 Mar 2026 15:22:04 +0100
| Newsgroups | gmane.comp.web.zope.plone.announce |
|---|---|
| Message-ID | <mailman.161088.1772482451.8001.plone-announce@lists.sourceforge.net> |
This is a multi-part message in MIME format.
--===============6995837535435700143==
Content-Type: multipart/alternative;
boundary="------------ZR2uD3OusNi1E6zY9tTPwlsJ"
Content-Language: en-GB
This is a multi-part message in MIME format.
--------------ZR2uD3OusNi1E6zY9tTPwlsJ
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
This is a copy of an advisory published on GitHub today:
https://github.com/plone/Products.isurlinportal/security/advisories/GHSA-43gx-6gv6-3jcp
*Possible open redirect when using more than 2 forward slashes
*
*Impact*
A url `/login?came_from=////evil.example` may redirect to an external
website after login.
Standard Plone is not affected, but if you have customised the login,
for example with add-ons, you might be affected. You can try the url to
check if you are affected or not.
*Patches*
The problem has been patched in `Products.isurlinportal`.
* Plone 6.2: upgrade to `Products.isurlinportal` 4.0.0.
* Plone 6.1: upgrade to `Products.isurlinportal` 3.1.0.
* Plone 6.0: upgrade to `Products.isurlinportal` 2.1.0.
* Older Plone versions don't have security support anymore.
*Workarounds*
There are no known workarounds.
*Background*
When you are anonymous and land on a page that requires a login, Plone
sends you to the login form. After successful login, Plone redirects you
back to the page you came from. Various other forms and pages have a
similar system.
This could get abused by an attacker to trick Plone into redirecting to
a different website. Plone checks the page that would be redirected to.
It is only accepted if it is within the Plone site domain or part of a
different trusted domain.
The main check for this is in the `Products.isurlinportal` package. A
lot of potentially malicious urls are already safely rejected, but here
a loop hole was found.
This was discovered during a penetration test by the CERT-EU Team.
Thank you Alessandro Pisa for contacting me for the Plone Security Team
and supplying a fix and tests.
Maurits van Rees
Plone/Zope Security Team
--------------ZR2uD3OusNi1E6zY9tTPwlsJ
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
</head>
<body>
<p>This is a copy of an advisory published on GitHub today:<br>
<a class="moz-txt-link-freetext" href="https://github.com/plone/Products.isurlinportal/security/advisories/GHSA-43gx-6gv6-3jcp">https://github.com/plone/Products.isurlinportal/security/advisories/GHSA-43gx-6gv6-3jcp</a></p>
<p><b>Possible open redirect when using more than 2 forward slashes<br>
</b><br>
<b>Impact</b><br>
A url `/login?came_from=////evil.example` may redirect to an
external website after login.<br>
<br>
Standard Plone is not affected, but if you have customised the
login, for example with add-ons, you might be affected. You can
try the url to check if you are affected or not.<br>
<br>
<b>Patches</b><br>
The problem has been patched in `Products.isurlinportal`.<br>
<br>
* Plone 6.2: upgrade to `Products.isurlinportal` 4.0.0.<br>
* Plone 6.1: upgrade to `Products.isurlinportal` 3.1.0.<br>
* Plone 6.0: upgrade to `Products.isurlinportal` 2.1.0.<br>
* Older Plone versions don't have security support anymore.<br>
<br>
<b>Workarounds</b><br>
There are no known workarounds.<br>
<br>
<b>Background</b><br>
When you are anonymous and land on a page that requires a login,
Plone sends you to the login form. After successful login, Plone
redirects you back to the page you came from. Various other forms
and pages have a similar system.<br>
This could get abused by an attacker to trick Plone into
redirecting to a different website. Plone checks the page that
would be redirected to. It is only accepted if it is within the
Plone site domain or part of a different trusted domain.<br>
The main check for this is in the `Products.isurlinportal`
package. A lot of potentially malicious urls are already safely
rejected, but here a loop hole was found.<br>
<br>
This was discovered during a penetration test by the CERT-EU Team.</p>
<p>Thank you Alessandro Pisa for contacting me for the Plone
Security Team and supplying a fix and tests.</p>
<p>Maurits van Rees<br>
Plone/Zope Security Team</p>
<p><br>
</p>
<p><br>
</p>
</body>
</html>
--------------ZR2uD3OusNi1E6zY9tTPwlsJ--
--===============6995837535435700143==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============6995837535435700143==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Plone-Announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-announce
--===============6995837535435700143==--