oss-sec mailing list archives
Re: CVE request: plone privilege escalation flaw
From: Josh Bressers <bressers () redhat com>
Date: Tue, 12 Jul 2011 14:30:11 -0400 (EDT)
Please use CVE-2011-2528. Thanks. -- JB ----- Original Message -----
Looks like the previous fix for Plone/Zope (CVE-2011-0720) caused a new privilege escalation flaw in Plone 3.x and 4.x. Could a CVE be assigned? References: https://bugzilla.redhat.com/show_bug.cgi?id=718824 http://plone.org/products/plone/security/advisories/20110622 http://plone.org/products/plone-hotfix/releases/20110622 http://secunia.com/advisories/45111 Thanks. -- Vincent Danen / Red Hat Security Response Team
Current thread:
- CVE request: plone privilege escalation flaw Vincent Danen (Jul 04)
- Re: CVE request: plone privilege escalation flaw Josh Bressers (Jul 12)