MEDIUM
plone: authentication flaw in login form
Published Apr 23, 2009
6.0
MEDIUMCVSS 2.0
EPSS 0.97%
Description
The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://osvdb.org/53975 vdb-entryx_refsource_OSVDB
- http://plone.org/products/plone/security/advisories/cve-2009-0662 x_refsource_CONFIRMPatchVendor Advisory
- http://secunia.com/advisories/34840 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.securityfocus.com/bid/34664 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2009-0662 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=497493 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50061 vdb-entryx_refsource_XF
- https://github.com/advisories/GHSA-pq3x-96c3-xgjg Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2009-17.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2009-0662
- https://www.cve.org/CVERecord?id=CVE-2009-0662
| Link | Providers | Tags |
|---|---|---|
| http://osvdb.org/53975 | vdb-entryx_refsource_OSVDB | |
| http://plone.org/products/plone/security/advisories/cve-2009-0662 | x_refsource_CONFIRMPatchVendor Advisory | |
| http://secunia.com/advisories/34840 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.securityfocus.com/bid/34664 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2009-0662 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=497493 | Issue Tracking | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/50061 | vdb-entryx_refsource_XF | |
| https://github.com/advisories/GHSA-pq3x-96c3-xgjg | Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2009-17.yaml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2009-0662 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-0662 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 23, 2009
Updated Aug 7, 2024
Reserved Feb 22, 2009
Link CVE-2009-0662
CISA Vulnrichment
GHSA-PQ3X-96C3-XGJG Updated n/a