VYPR

PyPI package

plone.app.dexterity

pkg:pypi/plone.app.dexterity

Vulnerabilities (3)

  • CVE-2020-28736HigDec 30, 2020
    affected < 2.6.8fixed 2.6.8

    Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).

  • CVE-2020-28735HigDec 30, 2020
    affected < 2.6.8fixed 2.6.8

    Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).

  • CVE-2020-28734HigDec 30, 2020
    affected < 2.6.8fixed 2.6.8

    Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.