CVE-2011-4030

UnknownEPSS 1.97%

Last modified

CVE-2011-4030 is a vulnerability of currently unknown severity. The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.. EPSS estimates a 1.97% chance of exploitation in the next 30 days.

Description

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.

Metrics

EPSS Probability
1.97%

77.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
PloneCmfeditions2.0a1
PloneCmfeditions2.0b1
PloneCmfeditions2.0b2
PloneCmfeditions2.0b3
PloneCmfeditions2.0b4
PloneCmfeditions2.0b5
PloneCmfeditions2.0b6
PloneCmfeditions2.0b7
PloneCmfeditions2.0b8
PloneCmfeditions2.0b9
PlonePlone4.0
PlonePlone4.0.1
PlonePlone4.0.2
PlonePlone4.0.3
PlonePlone4.0.4
PlonePlone4.0.5
PlonePlone4.0.6.1
PlonePlone4.0.7
PlonePlone4.0.8
PlonePlone4.0.9
PlonePlone4.1
PlonePlone4.2
PlonePlone4.2a1
PlonePlone4.2a2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2011-4030?
The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.
How severe is CVE-2011-4030?
Severity scoring for CVE-2011-4030 is pending analysis. The EPSS model estimates a 1.97% probability of exploitation in the next 30 days.
How do I fix CVE-2011-4030?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2011-4030?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST