Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-23054


An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).


Published

2024-02-05T16:15:55.437

Last Modified

2024-11-21T08:56:52.347

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-427
  • Type: Secondary
    CWE-427

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application plone plone_docker_official_image 5.2.13 Yes

References