CVE Vulnerabilities

CVE-2013-4196

Published: Mar 11, 2014 | Modified: Mar 12, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restrict access to internal methods, which allows remote attackers to obtain sensitive information via a crafted request.

Affected Software

Name Vendor Start Version End Version
Plone Plone 4.3 (including) 4.3 (including)
Plone Plone 4.3.1 (including) 4.3.1 (including)

References