Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-4030


The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.


Published

2011-10-10T10:55:06.957

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 9.3 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application plone cmfeditions 2.0a1 Yes
Application plone cmfeditions 2.0b1 Yes
Application plone cmfeditions 2.0b2 Yes
Application plone cmfeditions 2.0b3 Yes
Application plone cmfeditions 2.0b4 Yes
Application plone cmfeditions 2.0b5 Yes
Application plone cmfeditions 2.0b6 Yes
Application plone cmfeditions 2.0b7 Yes
Application plone cmfeditions 2.0b8 Yes
Application plone cmfeditions 2.0b9 Yes
Application plone plone 4.0 Yes
Application plone plone 4.0.1 Yes
Application plone plone 4.0.2 Yes
Application plone plone 4.0.3 Yes
Application plone plone 4.0.4 Yes
Application plone plone 4.0.5 Yes
Application plone plone 4.0.6.1 Yes
Application plone plone 4.0.7 Yes
Application plone plone 4.0.8 Yes
Application plone plone 4.0.9 Yes
Application plone plone 4.1 Yes
Application plone plone 4.2 Yes
Application plone plone 4.2a1 Yes
Application plone plone 4.2a2 Yes

References