Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-23756


The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.


Published

2024-02-08T21:15:08.380

Last Modified

2025-05-15T20:15:44.510

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application plone plone 5.2.13 Yes

References