Junglewise Threat Intelligence

CVE-2011-2528: Plone and Zope2 privilege escalation via incorrect security fix

CVE-2011-2528 · Severity: high · CVSS 7.5 · Published 2018-07-23

Technologies: plone (PyPI), Zope2 (PyPI). Vendors: PyPI.

Executive brief

Plone and Zope are popular open-source content management systems and web application frameworks used to build and manage websites. A serious security flaw was discovered that could allow an unauthorized person to gain elevated administrative privileges on the site. This could lead to unauthorized access to sensitive data, modification of website content, or disruption of services. The issue was caused by an incomplete fix for a previous security problem, and administrators are advised to apply the latest security patches immediately.

Technical details

An unspecified privilege escalation vulnerability exists in Zope 2.12.x (before 2.12.19), Zope 2.13.x (before 2.13.8), and Plone 3.x (specifically when using PloneHotfix20110720). The root cause is an incorrect or incomplete fix for a previous vulnerability (CVE-2011-0720). While the exact technical vector is not detailed in the advisory, it is described as a 'highly serious' flaw that allows attackers to gain privileges via unspecified vectors. The vulnerability is reachable over the network without authentication. Fixes are available in Zope 2.12.19, Zope 2.13.8, and Plone 3.3.6 (or via PloneHotfix20110622).

Affected products

  • Plone Foundation Plone >= 3.3.2, < 3.3.6
  • Zope Foundation Zope2 >= 2.12.0, < 2.12.19; >= 2.13.0, < 2.13.8

Timeline

  • 2011-06-22: patched: PloneHotfix20110622 released
  • 2011-06-28: advisory: Zope security hotfix announcement
  • 2011-07-19: disclosed: NVD publication date

References

Related threats