URGENT / ACTION REQUIRED: Plone security vulnerability, hotfix 20150910

nguyen-z4DKO/[email protected] Thu, 10 Sep 2015 11:23:56 -0500
Newsgroups gmane.comp.web.zope.plone.devel,gmane.comp.web.zope.plone.user
Message-ID <[email protected]>
--===============2466015501832742528==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_FA393B9C-8CAD-4B75-8619-F84B9F11BCFD"


--Apple-Mail=_FA393B9C-8CAD-4B75-8619-F84B9F11BCFD
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

The Plone security team is releasing the following hotfix that affects =
all current Plone versions.

Please make arrangements to install this hotfix as soon as possible.  =
See below for more information.

=
https://plone.org/products/plone/security/advisories/20150910-announcement=
 =
<https://plone.org/products/plone/security/advisories/20150910-announcemen=
t>=20

https://plone.org/products/plone-hotfix/releases/20150910 =
<https://plone.org/products/plone-hotfix/releases/20150910>=20

Security vulnerability: 20150910 - Multiple vectors
Patches to Zope and Plone for a variety of issues.
Versions Affected: All current Plone versions.=20
Versions Not Affected: None.

Nature of vulnerability: Allows creation of members by anonymous users =
on sites that have self-registration enabled.

The patch can be added to buildouts as Products.PloneHotfix20150910 =
(available from PyPI) or downloaded from Plone.org

This patch is compatible with all supported Plone versions (i.e. Plone =
3, Plone 4, Plone 5). It may work on earlier versions of Plone, but as =
these are unsupported they have undergone less testing.

This fix covers vulnerabilities spanning multiple versions of Plone.

Immediate Measures You Should Take
Disable self-registration until you have applied the patch.

Installation
Full installation instructions are available on the HotFix release =
page=C2=A0 <https://plone.org/products/plone-hotfix/releases/20150910>.

Extra Help
Should you not have in-house server administrators or a service =
agreement looking after your website, you can find consulting companies =
at plone.com/providers=C2=A0 <http://plone.com/providers>and =
plone.org/support/network=C2=A0 <https://plone.org/support/network>.

There is also free support=C2=A0 <https://plone.org/support>available =
online via Plone mailing lists and the Plone IRC channels.

Questions and Answers
Q. What will be involved in applying the patch?=20
A. Patches are made available as tarball-style archives that may be =
unpacked into the =E2=80=9Cproducts=E2=80=9D folder of a buildout =
installation and as Python packages that may be installed by editing a =
buildout configuration file and running buildout. Patching is generally =
easy and quick to accomplish.=20

Q: How were these vulnerability found?=20
A: The majority of issues were found as part of audits performed by the =
Plone Security team. A subset were reported by users. More details will =
be available upon release of the patch.

Q: My site is highly visible and mission-critical. I hear the patch has =
already been developed. Can I get the fix before the release date?=20
A: No. The patch will be made available to all users at the same time . =
There are no exceptions.

Q: If the patch has been developed already, why isn't it made available =
to the public now?=20
A: The Security Team is still testing the patch and running various =
scenarios thoroughly. The team is also making sure everybody has =
appropriate time to plan to patch their Plone installation(s). Some =
consultancy organizations have hundreds of sites to patch and need the =
extra time to coordinate their efforts with their clients.

Q: How does one exploit the vulnerability?=20
A: This information will not be made public until after the patch is =
made available.

General questions about this announcement , Plone patching procedures, =
and availability of support may be addressed to the Plone support =
forums=C2=A0 <https://plone.org/support>. If you have specific questions =
about this vulnerability or its handling, contact the Plone Security =
Team=C2=A0 <mailto:security-z4DKO/[email protected]>.

To report potentially security-related issues , e-mail the Plone =
Security Team at security-z4DKO/[email protected] <mailto:security-z4DKO/[email protected]>. We are =
always happy to credit individuals and companies who make responsible =
disclosures.

Information for Vulnerability Database Maintainers
We have already applied for CVE numbers for these issues. Further =
information on individual vulnerabilities (including CVSS scores, CWE =
identifiers and summaries) is available at the full vulnerability list =
<https://plone.org/products/plone/security/>=

--Apple-Mail=_FA393B9C-8CAD-4B75-8619-F84B9F11BCFD
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D""><h1 id=3D"parent-fieldname-title" style=3D"margin: 0px; =
padding: 0px; line-height: 32.5px; letter-spacing: -1px; font-size: =
1.625em; font-family: 'Helvetica Neue', Arial, FreeSans, sans-serif;" =
class=3D"documentFirstHeading"><span style=3D"font-family: Arial, =
FreeSans, sans-serif; font-size: 13px; font-weight: normal; =
letter-spacing: normal; line-height: 19.5px;" class=3D"">The Plone =
security team is releasing the following hotfix that affects all current =
Plone versions.</span></h1><div class=3D""><span style=3D"font-family: =
Arial, FreeSans, sans-serif; font-size: 13px; font-weight: normal; =
letter-spacing: normal; line-height: 19.5px;" class=3D""><br =
class=3D""></span></div><div class=3D""><span style=3D"font-family: =
Arial, FreeSans, sans-serif; font-size: 13px; font-weight: normal; =
letter-spacing: normal; line-height: 19.5px;" class=3D"">Please make =
arrangements to install this hotfix as soon as possible. &nbsp;See below =
for more information.</span></div><div class=3D""><br =
class=3D""></div><div class=3D""><font face=3D"Arial, FreeSans, =
sans-serif" size=3D"2" class=3D""><span style=3D"line-height: 19.5px;" =
class=3D""><a =
href=3D"https://plone.org/products/plone/security/advisories/20150910-anno=
uncement" =
class=3D"">https://plone.org/products/plone/security/advisories/20150910-a=
nnouncement</a>&nbsp;</span></font></div><div class=3D""><font =
face=3D"Arial, FreeSans, sans-serif" size=3D"2" class=3D""><span =
style=3D"line-height: 19.5px;" class=3D""><br =
class=3D""></span></font></div><div class=3D""><font class=3D"" =
face=3D"Arial, FreeSans, sans-serif" size=3D"2"><span class=3D"" =
style=3D"line-height: 19.5px;"><a =
href=3D"https://plone.org/products/plone-hotfix/releases/20150910" =
class=3D"">https://plone.org/products/plone-hotfix/releases/20150910</a>&n=
bsp;</span></font></div><div class=3D""><span style=3D"font-weight: =
normal;" class=3D""><br class=3D""></span></div><h1 =
id=3D"parent-fieldname-title" style=3D"margin: 0px; padding: 0px; =
font-size: 1.625em; font-family: 'Helvetica Neue', Arial, FreeSans, =
sans-serif; line-height: 32.5px; letter-spacing: -1px;" =
class=3D"documentFirstHeading">Security vulnerability: 20150910 - =
Multiple vectors</h1><div id=3D"viewlet-below-content-title" =
style=3D"margin: 0px; padding: 0px; font-family: Arial, FreeSans, =
sans-serif; font-size: 16px; line-height: 24px;" class=3D""><div =
style=3D"margin: 0px; padding: 0px;" =
class=3D"RatingViewlet"></div></div><div =
id=3D"parent-fieldname-description" style=3D"margin: 0px 0px 1em; =
padding: 0px; color: gray !important; font-weight: bold !important; =
font-size: 1em !important; font-family: 'Helvetica Neue', Arial, =
FreeSans, sans-serif !important;" class=3D"documentDescription">Patches =
to Zope and Plone for a variety of issues.</div><div =
id=3D"viewlet-above-content-body" style=3D"margin: 0px; padding: 0px; =
font-family: Arial, FreeSans, sans-serif; font-size: 16px; line-height: =
24px;" class=3D""></div><div id=3D"content-core" style=3D"margin: 0px; =
padding: 0px; font-family: Arial, FreeSans, sans-serif; font-size: 16px; =
line-height: 24px;" class=3D""><div id=3D"parent-fieldname-text" =
style=3D"margin: 0px; padding: 0px;" class=3D"plain"><p style=3D"margin: =
0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" =
class=3D""><b style=3D"margin: 0px; padding: 0px;" class=3D"">Versions =
Affected:&nbsp;</b>All current Plone versions.&nbsp;<br style=3D"margin: =
0px; padding: 0px;" class=3D""><b style=3D"margin: 0px; padding: 0px;" =
class=3D"">Versions Not Affected:&nbsp;</b>None.</p><p style=3D"margin: =
0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" =
class=3D""><strong style=3D"margin: 0px; padding: 0px;" class=3D"">Nature =
of vulnerability:</strong>&nbsp;Allows creation of members by anonymous =
users on sites that have self-registration enabled.</p><p style=3D"margin:=
 0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" =
class=3D"">The patch can be added to buildouts as =
Products.PloneHotfix20150910 (available from PyPI) or downloaded from <a =
href=3D"http://Plone.org" class=3D"">Plone.org</a></p><p style=3D"margin: =
0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" =
class=3D"">This patch is compatible with all supported Plone versions =
(i.e. Plone 3, Plone 4, Plone 5). It may work on earlier versions of =
Plone, but as these are unsupported they have undergone less =
testing.</p><p style=3D"margin: 0px 0px 1em; padding: 0px; font-size: =
13px; line-height: 1.5em;" class=3D""><i style=3D"margin: 0px; padding: =
0px;" class=3D"">This fix covers vulnerabilities spanning multiple =
versions of Plone.</i></p><h3 style=3D"margin: 0.5em 0px 0px; padding: =
0px; font-size: 1.125em; font-family: 'Helvetica Neue', Arial, FreeSans, =
sans-serif; line-height: 22.5px; color: rgb(68, 68, 68);" =
class=3D"">Immediate Measures You Should Take</h3><p style=3D"margin: =
0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" =
class=3D"">Disable self-registration until you have applied the =
patch.</p><h3 style=3D"margin: 0.5em 0px 0px; padding: 0px; font-size: =
1.125em; font-family: 'Helvetica Neue', Arial, FreeSans, sans-serif; =
line-height: 22.5px; color: rgb(68, 68, 68);" =
class=3D"">Installation</h3><p style=3D"margin: 0px 0px 1em; padding: =
0px; font-size: 13px; line-height: 1.5em;" class=3D"">Full installation =
instructions are available on the&nbsp;<a =
href=3D"https://plone.org/products/plone-hotfix/releases/20150910" =
style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: =
none; color: rgb(66, 117, 151); border-bottom-width: 1px; =
border-bottom-style: solid; border-bottom-color: rgb(204, 204, 204);" =
class=3D"">HotFix release page&nbsp;</a>.</p><h3 style=3D"margin: 0.5em =
0px 0px; padding: 0px; font-size: 1.125em; font-family: 'Helvetica =
Neue', Arial, FreeSans, sans-serif; line-height: 22.5px; color: rgb(68, =
68, 68);" class=3D"">Extra Help</h3><p style=3D"margin: 0px 0px 1em; =
padding: 0px; font-size: 13px; line-height: 1.5em;" class=3D"">Should =
you not have in-house server administrators or a service agreement =
looking after your website, you can find consulting companies at&nbsp;<a =
href=3D"http://plone.com/providers" target=3D"_self" title=3D"" =
style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: =
none; color: rgb(66, 117, 151); border-bottom-width: 1px; =
border-bottom-style: solid; border-bottom-color: rgb(204, 204, 204);" =
class=3D"external-link">plone.com/providers&nbsp;</a>and&nbsp;<a =
href=3D"https://plone.org/support/network" style=3D"margin: 0px; =
padding: 0px; outline: none; text-decoration: none; color: rgb(66, 117, =
151); border-bottom-width: 1px; border-bottom-style: solid; =
border-bottom-color: rgb(204, 204, 204);" =
class=3D"external-link">plone.org/support/network&nbsp;</a>.</p><p =
style=3D"margin: 0px 0px 1em; padding: 0px; font-size: 13px; =
line-height: 1.5em;" class=3D"">There is also&nbsp;<a =
href=3D"https://plone.org/support" style=3D"margin: 0px; padding: 0px; =
outline: none; text-decoration: none; color: rgb(66, 117, 151); =
border-bottom-width: 1px; border-bottom-style: solid; =
border-bottom-color: rgb(204, 204, 204);" class=3D"">free =
support&nbsp;</a>available online via Plone mailing lists and the Plone =
IRC channels.</p><hr style=3D"margin: 0px; padding: 0px;" class=3D""><h2 =
style=3D"margin: 0.5em 0px 0px; padding: 0px; font-size: 1.375em; =
font-family: 'Helvetica Neue', Arial, FreeSans, sans-serif; line-height: =
27.5px; color: rgb(68, 68, 68); letter-spacing: -1px;" =
class=3D"">Questions and Answers</h2><p style=3D"margin: 0px 0px 1em; =
padding: 0px; font-size: 13px; line-height: 1.5em;" class=3D""><b =
style=3D"margin: 0px; padding: 0px;" class=3D""></b><b style=3D"margin: =
0px; padding: 0px;" class=3D"">Q. What will be involved in applying the =
patch?&nbsp;<br style=3D"margin: 0px; padding: 0px;" class=3D""></b>A. =
Patches are made available as tarball-style archives that may be =
unpacked into the =E2=80=9Cproducts=E2=80=9D folder of a buildout =
installation and as Python packages that may be installed by editing a =
buildout configuration file and running buildout. Patching is generally =
easy and quick to accomplish.&nbsp;<b style=3D"margin: 0px; padding: =
0px;" class=3D""></b></p><p style=3D"margin: 0px 0px 1em; padding: 0px; =
font-size: 13px; line-height: 1.5em;" class=3D""><b style=3D"margin: =
0px; padding: 0px;" class=3D"">Q: How were these vulnerability =
found?&nbsp;<br style=3D"margin: 0px; padding: 0px;" class=3D""></b>A: =
The majority of issues were found as part of audits performed by the =
Plone Security team. A subset were reported by users. More details will =
be available upon release of the patch.</p><p style=3D"margin: 0px 0px =
1em; padding: 0px; font-size: 13px; line-height: 1.5em;" class=3D""><b =
style=3D"margin: 0px; padding: 0px;" class=3D""></b><b style=3D"margin: =
0px; padding: 0px;" class=3D"">Q: My site is highly visible and =
mission-critical. I hear the patch has already been developed. Can I get =
the fix before the release date?&nbsp;</b><br style=3D"margin: 0px; =
padding: 0px;" class=3D"">A: No. The patch will be made available =
to&nbsp;<b style=3D"margin: 0px; padding: 0px;" class=3D"">all users at =
the same time&nbsp;</b>. There are no exceptions.</p><p style=3D"margin: =
0px 0px 1em; padding: 0px; font-size: 13px; line-height: 1.5em;" =
class=3D""><b style=3D"margin: 0px; padding: 0px;" class=3D"">Q: If the =
patch has been developed already, why isn't it made available to the =
public now?&nbsp;<br style=3D"margin: 0px; padding: 0px;" =
class=3D""></b>A: The Security Team is still testing the patch and =
running various scenarios thoroughly. The team is also making sure =
everybody has appropriate time to plan to patch their Plone =
installation(s). Some consultancy organizations have hundreds of sites =
to patch and need the extra time to coordinate their efforts with their =
clients.</p><p style=3D"margin: 0px 0px 1em; padding: 0px; font-size: =
13px; line-height: 1.5em;" class=3D""><b style=3D"margin: 0px; padding: =
0px;" class=3D"">Q: How does one exploit the vulnerability?&nbsp;<br =
style=3D"margin: 0px; padding: 0px;" class=3D""></b>A: This information =
will not be made public until after the patch is made available.</p><p =
style=3D"margin: 0px 0px 1em; padding: 0px; font-size: 13px; =
line-height: 1.5em;" class=3D""><b style=3D"margin: 0px; padding: 0px;" =
class=3D"">General questions&nbsp;</b><b style=3D"margin: 0px; padding: =
0px;" class=3D"">about this announcement&nbsp;</b>, Plone patching =
procedures, and availability of support may be addressed to the&nbsp;<a =
href=3D"https://plone.org/support" style=3D"margin: 0px; padding: 0px; =
outline: none; text-decoration: none; color: rgb(66, 117, 151); =
border-bottom-width: 1px; border-bottom-style: solid; =
border-bottom-color: rgb(204, 204, 204);" class=3D"">Plone support =
forums&nbsp;</a>. If you have&nbsp;<b style=3D"margin: 0px; padding: =
0px;" class=3D"">specific questions&nbsp;</b>about this vulnerability or =
its handling, contact the&nbsp;<a href=3D"mailto:security-z4DKO/[email protected]" =
style=3D"margin: 0px; padding: 0px; outline: none; text-decoration: =
none; color: rgb(66, 117, 151); border-bottom-width: 1px; =
border-bottom-style: solid; border-bottom-color: rgb(204, 204, 204);" =
class=3D"">Plone Security Team&nbsp;</a>.</p><p style=3D"margin: 0px 0px =
1em; padding: 0px; font-size: 13px; line-height: 1.5em;" class=3D""><b =
style=3D"margin: 0px; padding: 0px;" class=3D"">To report potentially =
security-related issues&nbsp;</b><b style=3D"margin: 0px; padding: 0px;" =
class=3D"">,&nbsp;</b>e-mail the Plone Security Team at&nbsp;<a =
href=3D"mailto:security-z4DKO/[email protected]" style=3D"margin: 0px; padding: 0px; =
outline: none; text-decoration: none; color: rgb(66, 117, 151); =
border-bottom-width: 1px; border-bottom-style: solid; =
border-bottom-color: rgb(204, 204, 204);" =
class=3D"">security-z4DKO/[email protected]</a>. We are always happy to credit =
individuals and companies who make responsible disclosures.</p><h3 =
style=3D"margin: 0.5em 0px 0px; padding: 0px; font-size: 1.125em; =
font-family: 'Helvetica Neue', Arial, FreeSans, sans-serif; line-height: =
22.5px; color: rgb(68, 68, 68);" class=3D"">Information for =
Vulnerability Database Maintainers</h3><p style=3D"margin: 0px 0px 1em; =
padding: 0px; font-size: 13px; line-height: 1.5em;" class=3D"">We have =
already applied for CVE numbers for these issues. Further information on =
individual vulnerabilities (including CVSS scores, CWE identifiers and =
summaries) is available at&nbsp;<a =
href=3D"https://plone.org/products/plone/security/" style=3D"margin: =
0px; padding: 0px; outline: none; text-decoration: none; color: rgb(66, =
117, 151); border-bottom-width: 1px; border-bottom-style: solid; =
border-bottom-color: rgb(204, 204, 204);" class=3D"">the full =
vulnerability list</a></p></div></div></body></html>=

--Apple-Mail=_FA393B9C-8CAD-4B75-8619-F84B9F11BCFD--


--===============2466015501832742528==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------
Monitor Your Dynamic Infrastructure at Any Scale With Datadog!
Get real-time metrics from all of your servers, apps and tools
in one place.
SourceForge users - Click here to start your Free Trial of Datadog now!
http://pubads.g.doubleclick.net/gampad/clk?id=241902991&iu=/4140
--===============2466015501832742528==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Plone-developers mailing list
Plone-developers-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
https://lists.sourceforge.net/lists/listinfo/plone-developers

--===============2466015501832742528==--