CVE-2011-4030

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:plone:cmfeditions:2.0a1:*:*:*:*:*:*:*
cpe:2.3:a:plone:cmfeditions:2.0b1:*:*:*:*:*:*:*
cpe:2.3:a:plone:cmfeditions:2.0b2:*:*:*:*:*:*:*
cpe:2.3:a:plone:cmfeditions:2.0b3:*:*:*:*:*:*:*
cpe:2.3:a:plone:cmfeditions:2.0b4:*:*:*:*:*:*:*
cpe:2.3:a:plone:cmfeditions:2.0b5:*:*:*:*:*:*:*
cpe:2.3:a:plone:cmfeditions:2.0b6:*:*:*:*:*:*:*
cpe:2.3:a:plone:cmfeditions:2.0b7:*:*:*:*:*:*:*
cpe:2.3:a:plone:cmfeditions:2.0b8:*:*:*:*:*:*:*
cpe:2.3:a:plone:cmfeditions:2.0b9:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:4.0:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:4.0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:4.0.7:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:4.0.8:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:4.0.9:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:4.1:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:4.2:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:4.2a1:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:4.2a2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2011-10-10 10:55

Updated : 2023-12-10 11:03


NVD link : CVE-2011-4030

Mitre link : CVE-2011-4030

CVE.ORG link : CVE-2011-4030


JSON object : View

Products Affected

plone

  • cmfeditions
  • plone
CWE
CWE-264

Permissions, Privileges, and Access Controls