URGENT / ACTION REQUIRED: Plone security vulnerability, hotfix 20150910

nguyen-z4DKO/[email protected]
Newsgroups gmane.comp.web.zope.plone.devel,gmane.comp.web.zope.plone.user
Message-ID <[email protected]>
The Plone security team is releasing the following hotfix that affects all current Plone versions.

Please make arrangements to install this hotfix as soon as possible.  See below for more information.

https://plone.org/products/plone/security/advisories/20150910-announcement <https://plone.org/products/plone/security/advisories/20150910-announcement> 

https://plone.org/products/plone-hotfix/releases/20150910 <https://plone.org/products/plone-hotfix/releases/20150910> 

Security vulnerability: 20150910 - Multiple vectors
Patches to Zope and Plone for a variety of issues.
Versions Affected: All current Plone versions. 
Versions Not Affected: None.

Nature of vulnerability: Allows creation of members by anonymous users on sites that have self-registration enabled.

The patch can be added to buildouts as Products.PloneHotfix20150910 (available from PyPI) or downloaded from Plone.org

This patch is compatible with all supported Plone versions (i.e. Plone 3, Plone 4, Plone 5). It may work on earlier versions of Plone, but as these are unsupported they have undergone less testing.

This fix covers vulnerabilities spanning multiple versions of Plone.

Immediate Measures You Should Take
Disable self-registration until you have applied the patch.

Installation
Full installation instructions are available on the HotFix release page  <https://plone.org/products/plone-hotfix/releases/20150910>.

Extra Help
Should you not have in-house server administrators or a service agreement looking after your website, you can find consulting companies at plone.com/providers  <http://plone.com/providers>and plone.org/support/network  <https://plone.org/support/network>.

There is also free support  <https://plone.org/support>available online via Plone mailing lists and the Plone IRC channels.

Questions and Answers
Q. What will be involved in applying the patch? 
A. Patches are made available as tarball-style archives that may be unpacked into the “products” folder of a buildout installation and as Python packages that may be installed by editing a buildout configuration file and running buildout. Patching is generally easy and quick to accomplish. 

Q: How were these vulnerability found? 
A: The majority of issues were found as part of audits performed by the Plone Security team. A subset were reported by users. More details will be available upon release of the patch.

Q: My site is highly visible and mission-critical. I hear the patch has already been developed. Can I get the fix before the release date? 
A: No. The patch will be made available to all users at the same time . There are no exceptions.

Q: If the patch has been developed already, why isn't it made available to the public now? 
A: The Security Team is still testing the patch and running various scenarios thoroughly. The team is also making sure everybody has appropriate time to plan to patch their Plone installation(s). Some consultancy organizations have hundreds of sites to patch and need the extra time to coordinate their efforts with their clients.

Q: How does one exploit the vulnerability? 
A: This information will not be made public until after the patch is made available.

General questions about this announcement , Plone patching procedures, and availability of support may be addressed to the Plone support forums  <https://plone.org/support>. If you have specific questions about this vulnerability or its handling, contact the Plone Security Team  <mailto:security-z4DKO/[email protected]>.

To report potentially security-related issues , e-mail the Plone Security Team at security-z4DKO/[email protected] <mailto:security-z4DKO/[email protected]>. We are always happy to credit individuals and companies who make responsible disclosures.

Information for Vulnerability Database Maintainers
We have already applied for CVE numbers for these issues. Further information on individual vulnerabilities (including CVSS scores, CWE identifiers and summaries) is available at the full vulnerability list <https://plone.org/products/plone/security/>

------------------------------------------------------------------------------
Monitor Your Dynamic Infrastructure at Any Scale With Datadog!
Get real-time metrics from all of your servers, apps and tools
in one place.
SourceForge users - Click here to start your Free Trial of Datadog now!
http://pubads.g.doubleclick.net/gampad/clk?id=241902991&iu=/4140

_______________________________________________
Plone-developers mailing list
Plone-developers-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
https://lists.sourceforge.net/lists/listinfo/plone-developers
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.