Security vulnerability: 20151208 — Plone CMS: Open Source Content Management
"T. Kim Nguyen" <nguyen-z4DKO/[email protected]> Tue, 8 Dec 2015 09:19:56 -0600
| Newsgroups | gmane.comp.web.zope.plone.devel |
|---|---|
| Message-ID | <[email protected]> |
> https://plone.org/products/plone/security/advisories/20151208-announcement <https://plone.org/products/plone/security/advisories/20151208-announcement> Security vulnerability: 20151208 Patches to Plone for unauthorized disclosure of registered user information Versions Affected: All current Plone versions. Versions Not Affected: None. Nature of vulnerability: Allows unauthorized disclosure of registered user information The patch can be added to buildouts as Products.PloneHotfix20151208 (available from pypi.python.org <https://pypi.python.org/pypi?%3Aaction=search&term=Products.PloneHotfix20151208&submit=search>) or downloaded from Plone.org <https://plone.org/products/plone-hotfix/releases/20151208> This patch is compatible with all supported Plone versions (i.e. Plone 4, Plone 5). It may work on earlier versions of Plone, but as these are officially unsupported they have not undergone the same level of testing with the patch. Installation Full installation instructions are available on the HotFix release page <https://plone.org/products/plone-hotfix/releases/20151208>. Extra Help If you do not have in-house server administrators or a website maintenance service agreement, you can find consulting companies at plone.com/providers <http://plone.com/providers>and plone.org/support/network <https://plone.org/support/network>. There is also free support <https://plone.org/support>available online via the Plone IRC channel <http://plone.org/support> and the Plone community forum <http://community.plone.org/>. Thanks The Plone Security Team is grateful to Giovanni Monteiro Calanzani and Glauter de Sousa Vilela, who reported the vulnerability. Questions and Answers Q. What is involved in applying the patch? A. Patches are made available as tarball-style archives that may be unpacked into the “products” folder of a buildout installation and as Python packages that may be installed by editing a buildout configuration file and running buildout. Patching is generally easy and quick to accomplish. Q: My site is highly visible and mission-critical. I hear the patch has already been developed. Can I get the fix before the release date? A: Plone patches are always made available to all users at the same time. There are no exceptions. General questions about this announcement, Plone patching procedures, and availability of support may be addressed to the Plone support forums <https://plone.org/support>. If you have specific questions about this vulnerability or its handling, contact the Plone Security Team <mailto:security-z4DKO/[email protected]>directly. To report potentially security-related issues, e-mail the Plone Security Team directly at security-z4DKO/[email protected] <mailto:security-z4DKO/[email protected]>. We are always happy to credit individuals and companies who make responsible disclosures. The Plone Security Team is an all-volunteer team. If you'd like to help the team, as a developer, a tester, or as a financial sponsor, please email the team at security-z4DKO/[email protected] <mailto:security-z4DKO/[email protected]?subject=support%20for%20the%20Plone%20Security%20Team>. Information for Vulnerability Database Maintainers We have already applied for CVE numbers for these issues. Further information on individual vulnerabilities (including CVSS scores, CWE identifiers and summaries) is available at the full vulnerability list <https://plone.org/products/plone/security/> ------------------------------------------------------------------------------ Go from Idea to Many App Stores Faster with Intel(R) XDK Give your users amazing mobile app experiences with Intel(R) XDK. Use one codebase in this all-in-one HTML5 development environment. Design, debug & build mobile apps & 2D/3D high-impact games for multiple OSs. http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 _______________________________________________ Plone-developers mailing list Plone-developers-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org https://lists.sourceforge.net/lists/listinfo/plone-developers