CVE-2012-5507
Last modified
CVE-2012-5507 is a vulnerability of currently unknown severity. AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.. EPSS estimates a 0.93% chance of exploitation in the next 30 days.
Description
AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zope | Zope | 2.5.1 |
| Zope | Zope | 2.6.1 |
| Zope | Zope | 2.6.4 |
| Zope | Zope | 2.7.0 |
| Zope | Zope | 2.7.3 |
| Zope | Zope | 2.7.4 |
| Zope | Zope | 2.7.5 |
| Zope | Zope | 2.7.6 |
| Zope | Zope | 2.7.7 |
| Zope | Zope | 2.7.8 |
| Zope | Zope | 2.8.1 |
| Zope | Zope | 2.8.4 |
| Zope | Zope | 2.8.6 |
| Zope | Zope | 2.8.8 |
| Zope | Zope | 2.9.2 |
| Zope | Zope | 2.9.3 |
| Zope | Zope | 2.9.4 |
| Zope | Zope | 2.9.5 |
| Zope | Zope | 2.9.6 |
| Zope | Zope | 2.9.7 |
| Zope | Zope | 2.10.3 |
| Zope | Zope | 2.10.8 |
| Zope | Zope | 2.11.0 |
| Zope | Zope | 2.11.1 |
| Zope | Zope | 2.11.2 |
| Zope | Zope | 2.11.3 |
| Zope | Zope | 2.13.18 |
| Plone | Plone | <= 4.2.2 |
| Plone | Plone | 1.0 |
| Plone | Plone | 1.0.1 |
| Plone | Plone | 1.0.2 |
| Plone | Plone | 1.0.3 |
| Plone | Plone | 1.0.4 |
| Plone | Plone | 1.0.5 |
| Plone | Plone | 1.0.6 |
| Plone | Plone | 2.0 |
| Plone | Plone | 2.0.1 |
| Plone | Plone | 2.0.2 |
| Plone | Plone | 2.0.3 |
| Plone | Plone | 2.0.4 |
| Plone | Plone | 2.0.5 |
| Plone | Plone | 2.1 |
| Plone | Plone | 2.1.1 |
| Plone | Plone | 2.1.2 |
| Plone | Plone | 2.1.3 |
| Plone | Plone | 2.1.4 |
| Plone | Plone | 2.5 |
| Plone | Plone | 2.5.1 |
| Plone | Plone | 2.5.2 |
| Plone | Plone | 2.5.3 |
Showing 50 of 93 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-5507?
How severe is CVE-2012-5507?
How do I fix CVE-2012-5507?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-5501at_download.py in Plone before 4.2.3 and 4.3 before beta 1 a…
- CVE-2012-5502Cross-site scripting (XSS) vulnerability in safe_html.py in …
- CVE-2012-5503ftp.py in Plone before 4.2.3 and 4.3 before beta 1 allows re…
- CVE-2012-5504Cross-site scripting (XSS) vulnerability in widget_traversal…
- CVE-2012-5505atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows r…
- CVE-2012-5506python_scripts.py in Plone before 4.2.3 and 4.3 before beta …
- CVE-2012-5508The error pages in Plone before 4.2.3 and 4.3 before beta 1 …
- CVE-2012-5509aeolus-configserver-setup in the Aeolas Configuration Server…
- CVE-2012-5510Xen 4.x, when downgrading the grant table version, does not …
- CVE-2012-5511Stack-based buffer overflow in the dirty video RAM tracking …
- CVE-2012-5512Array index error in the HVMOP_set_mem_access handler in Xen…
- CVE-2012-5513The XENMEM_exchange handler in Xen 4.2 and earlier does not …
Are you affected by CVE-2012-5507?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
