URGENT / ACTION REQUIRED: Plone security vulnerability, hotfix 20150910
nguyen-z4DKO/[email protected] Thu, 10 Sep 2015 11:23:56 -0500
| Newsgroups | gmane.comp.web.zope.plone.devel,gmane.comp.web.zope.plone.user |
|---|---|
| Message-ID | <[email protected]> |
--===============2466015501832742528== Content-Type: multipart/alternative; boundary="Apple-Mail=_FA393B9C-8CAD-4B75-8619-F84B9F11BCFD" --Apple-Mail=_FA393B9C-8CAD-4B75-8619-F84B9F11BCFD Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 The Plone security team is releasing the following hotfix that affects = all current Plone versions. Please make arrangements to install this hotfix as soon as possible. = See below for more information. = https://plone.org/products/plone/security/advisories/20150910-announcement= = <https://plone.org/products/plone/security/advisories/20150910-announcemen= t>=20 https://plone.org/products/plone-hotfix/releases/20150910 = <https://plone.org/products/plone-hotfix/releases/20150910>=20 Security vulnerability: 20150910 - Multiple vectors Patches to Zope and Plone for a variety of issues. Versions Affected: All current Plone versions.=20 Versions Not Affected: None. Nature of vulnerability: Allows creation of members by anonymous users = on sites that have self-registration enabled. The patch can be added to buildouts as Products.PloneHotfix20150910 = (available from PyPI) or downloaded from Plone.org This patch is compatible with all supported Plone versions (i.e. Plone = 3, Plone 4, Plone 5). It may work on earlier versions of Plone, but as = these are unsupported they have undergone less testing. This fix covers vulnerabilities spanning multiple versions of Plone. Immediate Measures You Should Take Disable self-registration until you have applied the patch. Installation Full installation instructions are available on the HotFix release = page=C2=A0 <https://plone.org/products/plone-hotfix/releases/20150910>. Extra Help Should you not have in-house server administrators or a service = agreement looking after your website, you can find consulting companies = at plone.com/providers=C2=A0 <http://plone.com/providers>and = plone.org/support/network=C2=A0 <https://plone.org/support/network>. There is also free support=C2=A0 <https://plone.org/support>available = online via Plone mailing lists and the Plone IRC channels. Questions and Answers Q. What will be involved in applying the patch?=20 A. Patches are made available as tarball-style archives that may be = unpacked into the =E2=80=9Cproducts=E2=80=9D folder of a buildout = installation and as Python packages that may be installed by editing a = buildout configuration file and running buildout. Patching is generally = easy and quick to accomplish.=20 Q: How were these vulnerability found?=20 A: The majority of issues were found as part of audits performed by the = Plone Security team. A subset were reported by users. More details will = be available upon release of the patch. Q: My site is highly visible and mission-critical. I hear the patch has = already been developed. Can I get the fix before the release date?=20 A: No. The patch will be made available to all users at the same time . = There are no exceptions. Q: If the patch has been developed already, why isn't it made available = to the public now?=20 A: The Security Team is still testing the patch and running various = scenarios thoroughly. The team is also making sure everybody has = appropriate time to plan to patch their Plone installation(s). Some = consultancy organizations have hundreds of sites to patch and need the = extra time to coordinate their efforts with their clients. Q: How does one exploit the vulnerability?=20 A: This information will not be made public until after the patch is = made available. General questions about this announcement , Plone patching procedures, = and availability of support may be addressed to the Plone support = forums=C2=A0 <https://plone.org/support>. If you have specific questions = about this vulnerability or its handling, contact the Plone Security = Team=C2=A0 <mailto:security-z4DKO/[email protected]>. To report potentially security-related issues , e-mail the Plone = Security Team at security-z4DKO/[email protected] <mailto:security-z4DKO/[email protected]>. We are = always happy to credit individuals and companies who make responsible = disclosures. Information for Vulnerability Database Maintainers We have already applied for CVE numbers for these issues. Further = information on individual vulnerabilities (including CVSS scores, CWE = identifiers and summaries) is available at the full vulnerability list = <https://plone.org/products/plone/security/>= --Apple-Mail=_FA393B9C-8CAD-4B75-8619-F84B9F11BCFD Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 <html><head><meta http-equiv=3D"Content-Type" content=3D"text/html = charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; = -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" = class=3D""><h1 id=3D"parent-fieldname-title" style=3D"margin: 0px; = padding: 0px; line-height: 32.5px; letter-spacing: -1px; font-size: = 1.625em; font-family: 'Helvetica Neue', Arial, FreeSans, sans-serif;" = class=3D"documentFirstHeading"><span style=3D"font-family: Arial, = FreeSans, sans-serif; font-size: 13px; font-weight: normal; = letter-spacing: normal; line-height: 19.5px;" class=3D"">The Plone = security team is releasing the following hotfix that affects all current = Plone versions.</span></h1><div class=3D""><span style=3D"font-family: = Arial, FreeSans, sans-serif; font-size: 13px; font-weight: normal; = letter-spacing: normal; line-height: 19.5px;" class=3D""><br = class=3D""></span></div><div class=3D""><span style=3D"font-family: = Arial, FreeSans, sans-serif; font-size: 13px; font-weight: normal; = letter-spacing: normal; line-height: 19.5px;" class=3D"">Please make = arrangements to install this hotfix as soon as possible. See below = for more information.</span></div><div class=3D""><br = class=3D""></div><div class=3D""><font face=3D"Arial, FreeSans, = sans-serif" size=3D"2" class=3D""><span style=3D"line-height: 19.5px;" = class=3D""><a = href=3D"https://plone.org/products/plone/security/advisories/20150910-anno= uncement" = class=3D"">https://plone.org/products/plone/security/advisories/20150910-a= nnouncement</a> </span></font></div><div class=3D""><font = face=3D"Arial, FreeSans, sans-serif" size=3D"2" class=3D""><span = style=3D"line-height: 19.5px;" class=3D""><br = class=3D""></span></font></div><div class=3D""><font class=3D"" = face=3D"Arial, FreeSans, sans-serif" size=3D"2"><span class=3D"" = style=3D"line-height: 19.5px;"><a = href=3D"https://plone.org/products/plone-hotfix/releases/20150910" = class=3D"">https://plone.org/products/plone-hotfix/releases/20150910</a>&n= bsp;</span></font></div><div class=3D""><span style=3D"font-weight: = normal;" class=3D""><br class=3D""></span></div><h1 = id=3D"parent-fieldname-title" style=3D"margin: 0px; padding: 0px; = font-size: 1.625em; font-family: 'Helvetica Neue', Arial, FreeSans, = sans-serif; line-height: 32.5px; letter-spacing: -1px;" = class=3D"documentFirstHeading">Security vulnerability: 20150910 - = Multiple vectors</h1><div id=3D"viewlet-below-content-title" = style=3D"margin: 0px; padding: 0px; font-family: Arial, FreeSans, = sans-serif; font-size: 16px; line-height: 24px;" class=3D""><div = style=3D"margin: 0px; padding: 0px;" = class=3D"RatingViewlet"></div></div><div = id=3D"parent-fieldname-description" style=3D"margin: 0px 0px 1em; = padding: 0px; color: gray !important; font-weight: bold !important; = font-size: 1em !important; font-family: 'Helvetica Neue', Arial, = FreeSans, sans-serif !important;" class=3D"documentDescription">Patches = to Zope and Plone for a variety of issues.</div><div = id=3D"viewlet-above-content-body" style=3D"margin: 0px; padding: 0px; = font-family: Arial, FreeSans, sans-serif; font-size: 16px; line-height: = 24px;" class=3D""></div><div id=3D"content-core" style=3D"margin: 0px; = padding: 0px; font-family: Arial, FreeSans, sans-serif; font-size: 16px; = line-height: 24px;" class=3D""><div id=3D"parent-fieldname-text" = style=3D"margin: 0px; padding: 0px;" class=3D"plain"><p style=3D"margin: = 0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" = class=3D""><b style=3D"margin: 0px; padding: 0px;" class=3D"">Versions = Affected: </b>All current Plone versions. <br style=3D"margin: = 0px; padding: 0px;" class=3D""><b style=3D"margin: 0px; padding: 0px;" = class=3D"">Versions Not Affected: </b>None.</p><p style=3D"margin: = 0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" = class=3D""><strong style=3D"margin: 0px; padding: 0px;" class=3D"">Nature = of vulnerability:</strong> Allows creation of members by anonymous = users on sites that have self-registration enabled.</p><p style=3D"margin:= 0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" = class=3D"">The patch can be added to buildouts as = Products.PloneHotfix20150910 (available from PyPI) or downloaded from <a = href=3D"http://Plone.org" class=3D"">Plone.org</a></p><p style=3D"margin: = 0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" = class=3D"">This patch is compatible with all supported Plone versions = (i.e. Plone 3, Plone 4, Plone 5). It may work on earlier versions of = Plone, but as these are unsupported they have undergone less = testing.</p><p style=3D"margin: 0px 0px 1em; padding: 0px; font-size: = 13px; line-height: 1.5em;" class=3D""><i style=3D"margin: 0px; padding: = 0px;" class=3D"">This fix covers vulnerabilities spanning multiple = versions of Plone.</i></p><h3 style=3D"margin: 0.5em 0px 0px; padding: = 0px; font-size: 1.125em; font-family: 'Helvetica Neue', Arial, FreeSans, = sans-serif; line-height: 22.5px; color: rgb(68, 68, 68);" = class=3D"">Immediate Measures You Should Take</h3><p style=3D"margin: = 0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" = class=3D"">Disable self-registration until you have applied the = patch.</p><h3 style=3D"margin: 0.5em 0px 0px; padding: 0px; font-size: = 1.125em; font-family: 'Helvetica Neue', Arial, FreeSans, sans-serif; = line-height: 22.5px; color: rgb(68, 68, 68);" = class=3D"">Installation</h3><p style=3D"margin: 0px 0px 1em; padding: = 0px; font-size: 13px; line-height: 1.5em;" class=3D"">Full installation = instructions are available on the <a = href=3D"https://plone.org/products/plone-hotfix/releases/20150910" = style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: = none; color: rgb(66, 117, 151); border-bottom-width: 1px; = border-bottom-style: solid; border-bottom-color: rgb(204, 204, 204);" = class=3D"">HotFix release page </a>.</p><h3 style=3D"margin: 0.5em = 0px 0px; padding: 0px; font-size: 1.125em; font-family: 'Helvetica = Neue', Arial, FreeSans, sans-serif; line-height: 22.5px; color: rgb(68, = 68, 68);" class=3D"">Extra Help</h3><p style=3D"margin: 0px 0px 1em; = padding: 0px; font-size: 13px; line-height: 1.5em;" class=3D"">Should = you not have in-house server administrators or a service agreement = looking after your website, you can find consulting companies at <a = href=3D"http://plone.com/providers" target=3D"_self" title=3D"" = style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: = none; color: rgb(66, 117, 151); border-bottom-width: 1px; = border-bottom-style: solid; border-bottom-color: rgb(204, 204, 204);" = class=3D"external-link">plone.com/providers </a>and <a = href=3D"https://plone.org/support/network" style=3D"margin: 0px; = padding: 0px; outline: none; text-decoration: none; color: rgb(66, 117, = 151); border-bottom-width: 1px; border-bottom-style: solid; = border-bottom-color: rgb(204, 204, 204);" = class=3D"external-link">plone.org/support/network </a>.</p><p = style=3D"margin: 0px 0px 1em; padding: 0px; font-size: 13px; = line-height: 1.5em;" class=3D"">There is also <a = href=3D"https://plone.org/support" style=3D"margin: 0px; padding: 0px; = outline: none; text-decoration: none; color: rgb(66, 117, 151); = border-bottom-width: 1px; border-bottom-style: solid; = border-bottom-color: rgb(204, 204, 204);" class=3D"">free = support </a>available online via Plone mailing lists and the Plone = IRC channels.</p><hr style=3D"margin: 0px; padding: 0px;" class=3D""><h2 = style=3D"margin: 0.5em 0px 0px; padding: 0px; font-size: 1.375em; = font-family: 'Helvetica Neue', Arial, FreeSans, sans-serif; line-height: = 27.5px; color: rgb(68, 68, 68); letter-spacing: -1px;" = class=3D"">Questions and Answers</h2><p style=3D"margin: 0px 0px 1em; = padding: 0px; font-size: 13px; line-height: 1.5em;" class=3D""><b = style=3D"margin: 0px; padding: 0px;" class=3D""></b><b style=3D"margin: = 0px; padding: 0px;" class=3D"">Q. What will be involved in applying the = patch? <br style=3D"margin: 0px; padding: 0px;" class=3D""></b>A. = Patches are made available as tarball-style archives that may be = unpacked into the =E2=80=9Cproducts=E2=80=9D folder of a buildout = installation and as Python packages that may be installed by editing a = buildout configuration file and running buildout. Patching is generally = easy and quick to accomplish. <b style=3D"margin: 0px; padding: = 0px;" class=3D""></b></p><p style=3D"margin: 0px 0px 1em; padding: 0px; = font-size: 13px; line-height: 1.5em;" class=3D""><b style=3D"margin: = 0px; padding: 0px;" class=3D"">Q: How were these vulnerability = found? <br style=3D"margin: 0px; padding: 0px;" class=3D""></b>A: = The majority of issues were found as part of audits performed by the = Plone Security team. A subset were reported by users. More details will = be available upon release of the patch.</p><p style=3D"margin: 0px 0px = 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" class=3D""><b = style=3D"margin: 0px; padding: 0px;" class=3D""></b><b style=3D"margin: = 0px; padding: 0px;" class=3D"">Q: My site is highly visible and = mission-critical. I hear the patch has already been developed. Can I get = the fix before the release date? </b><br style=3D"margin: 0px; = padding: 0px;" class=3D"">A: No. The patch will be made available = to <b style=3D"margin: 0px; padding: 0px;" class=3D"">all users at = the same time </b>. There are no exceptions.</p><p style=3D"margin: = 0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" = class=3D""><b style=3D"margin: 0px; padding: 0px;" class=3D"">Q: If the = patch has been developed already, why isn't it made available to the = public now? <br style=3D"margin: 0px; padding: 0px;" = class=3D""></b>A: The Security Team is still testing the patch and = running various scenarios thoroughly. The team is also making sure = everybody has appropriate time to plan to patch their Plone = installation(s). Some consultancy organizations have hundreds of sites = to patch and need the extra time to coordinate their efforts with their = clients.</p><p style=3D"margin: 0px 0px 1em; padding: 0px; font-size: = 13px; line-height: 1.5em;" class=3D""><b style=3D"margin: 0px; padding: = 0px;" class=3D"">Q: How does one exploit the vulnerability? <br = style=3D"margin: 0px; padding: 0px;" class=3D""></b>A: This information = will not be made public until after the patch is made available.</p><p = style=3D"margin: 0px 0px 1em; padding: 0px; font-size: 13px; = line-height: 1.5em;" class=3D""><b style=3D"margin: 0px; padding: 0px;" = class=3D"">General questions </b><b style=3D"margin: 0px; padding: = 0px;" class=3D"">about this announcement </b>, Plone patching = procedures, and availability of support may be addressed to the <a = href=3D"https://plone.org/support" style=3D"margin: 0px; padding: 0px; = outline: none; text-decoration: none; color: rgb(66, 117, 151); = border-bottom-width: 1px; border-bottom-style: solid; = border-bottom-color: rgb(204, 204, 204);" class=3D"">Plone support = forums </a>. If you have <b style=3D"margin: 0px; padding: = 0px;" class=3D"">specific questions </b>about this vulnerability or = its handling, contact the <a href=3D"mailto:security-z4DKO/[email protected]" = style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: = none; color: rgb(66, 117, 151); border-bottom-width: 1px; = border-bottom-style: solid; border-bottom-color: rgb(204, 204, 204);" = class=3D"">Plone Security Team </a>.</p><p style=3D"margin: 0px 0px = 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" class=3D""><b = style=3D"margin: 0px; padding: 0px;" class=3D"">To report potentially = security-related issues </b><b style=3D"margin: 0px; padding: 0px;" = class=3D"">, </b>e-mail the Plone Security Team at <a = href=3D"mailto:security-z4DKO/[email protected]" style=3D"margin: 0px; padding: 0px; = outline: none; text-decoration: none; color: rgb(66, 117, 151); = border-bottom-width: 1px; border-bottom-style: solid; = border-bottom-color: rgb(204, 204, 204);" = class=3D"">security-z4DKO/[email protected]</a>. We are always happy to credit = individuals and companies who make responsible disclosures.</p><h3 = style=3D"margin: 0.5em 0px 0px; padding: 0px; font-size: 1.125em; = font-family: 'Helvetica Neue', Arial, FreeSans, sans-serif; line-height: = 22.5px; color: rgb(68, 68, 68);" class=3D"">Information for = Vulnerability Database Maintainers</h3><p style=3D"margin: 0px 0px 1em; = padding: 0px; font-size: 13px; line-height: 1.5em;" class=3D"">We have = already applied for CVE numbers for these issues. Further information on = individual vulnerabilities (including CVSS scores, CWE identifiers and = summaries) is available at <a = href=3D"https://plone.org/products/plone/security/" style=3D"margin: = 0px; padding: 0px; outline: none; text-decoration: none; color: rgb(66, = 117, 151); border-bottom-width: 1px; border-bottom-style: solid; = border-bottom-color: rgb(204, 204, 204);" class=3D"">the full = vulnerability list</a></p></div></div></body></html>= --Apple-Mail=_FA393B9C-8CAD-4B75-8619-F84B9F11BCFD-- --===============2466015501832742528== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline ------------------------------------------------------------------------------ Monitor Your Dynamic Infrastructure at Any Scale With Datadog! Get real-time metrics from all of your servers, apps and tools in one place. SourceForge users - Click here to start your Free Trial of Datadog now! http://pubads.g.doubleclick.net/gampad/clk?id=241902991&iu=/4140 --===============2466015501832742528== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Plone-developers mailing list Plone-developers-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org https://lists.sourceforge.net/lists/listinfo/plone-developers --===============2466015501832742528==--