Junglewise Threat Intelligence

CVE-2012-5493: PYSEC-2014-35 - gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox

CVE-2012-5493 · Severity: low · CVSS 3.1 · Published 2014-09-30

Technologies: Plone, plone (PyPI). Vendors: Plone, PyPI.

Executive brief

Plone is a widely-used open-source content management system that runs websites and intranets for many organizations. This vulnerability allows authenticated users with certain administrative permissions to execute arbitrary Python code on the server by bypassing Plone's security sandbox. An attacker with such permissions could gain complete control over the application, access sensitive data, or disrupt service.

Technical details

The vulnerability exists in gtbn.py in Plone before version 4.2.3 and 4.3 beta 1, and is classified as a sandbox bypass (CWE-693, CWE-94). Remote authenticated users who possess certain permissions can bypass Plone's Python sandbox protection through unspecified vectors, allowing execution of arbitrary Python code on the server. The attack requires valid authentication credentials and specific administrative or developer-level permissions within Plone, but no user interaction beyond issuing the exploit. Patches are available in Plone 4.2.3 and later, as well as in 4.3 beta 1 and beyond.

Affected products

  • Plone Plone 3.0 through 4.2.2, and 4.3a1 through 4.3a2

Timeline

  • 2012-11-06: disclosed
  • 2012-11-06: patched
  • 2022-05-17: advisory

References

Related threats