Vulnerability Description
Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Plone | Plone | 2.5.5 |
References
- https://plone.org/security/hotfix/20171128/sandbox-escapeVendor Advisory
- https://plone.org/security/hotfix/20171128/sandbox-escapeVendor Advisory
FAQ
What is CVE-2017-1000483?
CVE-2017-1000483 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part ...
How severe is CVE-2017-1000483?
CVE-2017-1000483 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-1000483?
Check the references section above for vendor advisories and patch information. Affected products include: Plone Plone.