CVE-2011-3587
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 78.1%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 78.08% probability · 100th percentile
- CISA KEV
- Not listed
- Affected
- plone/plone · zope/zope
- Source
- secalert@redhat.com
References
- http://plone.org/products/plone-hotfix/releases/20110928Patch
- http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zipPatch
- http://plone.org/products/plone/security/advisories/20110928Patch, Vendor Advisory
- http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0Patch
- http://secunia.com/advisories/46221Vendor Advisory
- http://secunia.com/advisories/46323
- http://zope2.zope.org/news/security-vulnerability-announcement-cve-2011-3587Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=742297Patch
- http://plone.org/products/plone-hotfix/releases/20110928Patch
- http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zipPatch
- http://plone.org/products/plone/security/advisories/20110928Patch, Vendor Advisory
- http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0Patch
- http://secunia.com/advisories/46221Vendor Advisory
- http://secunia.com/advisories/46323
- http://zope2.zope.org/news/security-vulnerability-announcement-cve-2011-3587Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=742297Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.