CVE-2011-2528
Last modified
CVE-2011-2528 is a vulnerability of currently unknown severity. Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) PloneHotfix20110720 for Plone 3.x allows attackers to gain privileges via unspecified vectors, related to a "highly serious vulnerability." NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-0720.. EPSS estimates a 2.01% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) PloneHotfix20110720 for Plone 3.x allows attackers to gain privileges via unspecified vectors, related to a "highly serious vulnerability." NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-0720.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Plone | Plone Hotfix 20110720 | All versions |
| Plone | Plone | 3.0 |
| Plone | Plone | 3.0.1 |
| Plone | Plone | 3.0.2 |
| Plone | Plone | 3.0.3 |
| Plone | Plone | 3.0.4 |
| Plone | Plone | 3.0.5 |
| Plone | Plone | 3.0.6 |
| Plone | Plone | 3.1 |
| Plone | Plone | 3.1.1 |
| Plone | Plone | 3.1.2 |
| Plone | Plone | 3.1.3 |
| Plone | Plone | 3.1.4 |
| Plone | Plone | 3.1.5.1 |
| Plone | Plone | 3.1.6 |
| Plone | Plone | 3.1.7 |
| Plone | Plone | 3.2 |
| Plone | Plone | 3.2.1 |
| Plone | Plone | 3.2.2 |
| Plone | Plone | 3.2.3 |
| Plone | Plone | 3.3 |
| Plone | Plone | 3.3.1 |
| Plone | Plone | 3.3.2 |
| Plone | Plone | 3.3.3 |
| Plone | Plone | 3.3.4 |
| Plone | Plone | 3.3.5 |
| Plone | Plone | 3.3.6 |
| Plone | Plone | 4.0 |
| Plone | Plone | 4.0.1 |
| Plone | Plone | 4.0.2 |
| Plone | Plone | 4.0.3 |
| Plone | Plone | 4.0.4 |
| Plone | Plone | 4.0.5 |
| Plone | Plone | 4.0.6.1 |
| Plone | Plone | 4.0.7 |
| Plone | Plone | 4.0.8 |
| Plone | Plone | 4.1 |
| Zope | Zope | 2.12.0 |
| Zope | Zope | 2.12.1 |
| Zope | Zope | 2.12.2 |
| Zope | Zope | 2.12.3 |
| Zope | Zope | 2.12.4 |
| Zope | Zope | 2.12.5 |
| Zope | Zope | 2.12.6 |
| Zope | Zope | 2.12.7 |
| Zope | Zope | 2.12.8 |
| Zope | Zope | 2.12.9 |
| Zope | Zope | 2.12.10 |
| Zope | Zope | 2.12.11 |
| Zope | Zope | 2.12.12 |
Showing 50 of 64 affected configurations. See NVD for the full list.
References
- http://plone.org/products/plone-hotfix/releases/20110622Patch, Vendor Advisory
- http://plone.org/products/plone/security/advisories/20110622Patch, Vendor Advisory
- http://secunia.com/advisories/45056Vendor Advisory
- http://secunia.com/advisories/45111Vendor Advisory
- http://plone.org/products/plone-hotfix/releases/20110622Patch, Vendor Advisory
- http://plone.org/products/plone/security/advisories/20110622Patch, Vendor Advisory
- http://secunia.com/advisories/45056Vendor Advisory
- http://secunia.com/advisories/45111Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-2528?
How severe is CVE-2011-2528?
How do I fix CVE-2011-2528?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-2522Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2011-2523vsftpd 2.3.4 downloaded between 20110630 and 20110703 contai…9.8
- CVE-2011-2524Directory traversal vulnerability in soup-uri.c in SoupServe…
- CVE-2011-2525The qdisc_notify function in net/sched/sch_api.c in the Linu…7.8
- CVE-2011-2526Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.…
- CVE-2011-2527The change_process_uid function in os-posix.c in Qemu 0.14.0…
- CVE-2011-2529chan_sip.c in the SIP channel driver in Asterisk Open Source…
- CVE-2011-2530Buffer overflow in RSEds.dll in RSHWare.exe in the EDS Hardw…
- CVE-2011-2531Prosody 0.8.x before 0.8.1, when MySQL is used, assigns an i…
- CVE-2011-2532The json.decode function in util/json.lua in Prosody 0.8.x b…
- CVE-2011-2533The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28…
- CVE-2011-2534Buffer overflow in the clusterip_proc_write function in net/…7.8
Are you affected by CVE-2011-2528?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
