Junglewise Threat Intelligence

CVE-2006-4249: Plone PlonePAS group masquerading via anonymous registration

CVE-2006-4249 · Severity: medium · CVSS 5.9 · Published 2022-05-01

Technologies: plone (PyPI). Vendors: PyPI.

Executive brief

Plone is a content management system used for building websites and intranets. A security flaw in its authentication component allows unauthorized users to register accounts that impersonate system groups. This could allow an attacker to gain unauthorized access to restricted content or administrative functions intended only for specific groups.

Technical details

An unspecified vulnerability exists in the Plone Pluggable Authentication Service (PlonePAS) component of Plone versions 2.5 and 2.5.1. When the 'anonymous member registration' feature is enabled, a remote attacker can register a username that conflicts with or masquerades as a group identity. This logic flaw allows the attacker to inherit the permissions and access rights associated with that group. The vulnerability is exploitable over the network without prior authentication, though it requires the specific configuration of open registration to be active. The issue was addressed in Plone version 2.5.2 and via a security hotfix.

Affected products

  • Plone Foundation Plone 2.5, 2.5.1

Timeline

  • 2006-10-31: patched: Hotfix released by Plone Foundation
  • 2006-12-07: advisory: NVD published CVE-2006-4249
  • 2022-05-01: advisory: GitHub Advisory Database entry created

References

Related threats