CVE Vulnerabilities

CVE-2008-1395

Improper Authentication

Published: Mar 20, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Plone CMS does not record users authentication states, and implements the logout feature solely on the client side, which makes it easier for context-dependent attackers to reuse a logged-out session.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Plone_cmsPlone**
Zope-cmfploneUbuntudapper*
Zope-cmfploneUbuntuedgy*
Zope-cmfploneUbuntufeisty*
Zope-cmfploneUbuntugutsy*
Zope-cmfploneUbuntuhardy*
Zope-cmfploneUbuntuintrepid*
Zope-cmfploneUbuntuupstream*

Potential Mitigations

References