CVE-2021-33511
HIGHCVSS 7.5/10EPSS 1.20%
Last modified
CVE-2021-33511 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.. EPSS estimates a 1.20% chance of exploitation in the next 30 days.
Description
Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Plone | Plone | <= 5.2.4 |
References
- http://www.openwall.com/lists/oss-security/2021/05/22/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/05/22/1Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-33511?
Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.
How severe is CVE-2021-33511?
CVE-2021-33511 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.20% probability of exploitation in the next 30 days.
How do I fix CVE-2021-33511?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-33506jitsi-meet-prosody in Jitsi Meet before 2.0.5963-1 does not …7.5
- CVE-2021-33507Zope Products.CMFCore before 2.5.1 and Products.PluggableAut…6.1
- CVE-2021-33508Plone through 5.2.4 allows XSS via a full name that is misha…5.4
- CVE-2021-33509Plone through 5.2.4 allows remote authenticated managers to …9.9
- CVE-2021-3351OpenPLC runtime V3 through 2016-03-14 allows stored XSS via …5.4
- CVE-2021-33510Plone through 5.2.4 allows remote authenticated managers to …4.3
- CVE-2021-33512Plone through 5.2.4 allows stored XSS attacks (by a Contribu…5.4
- CVE-2021-33513Plone through 5.2.4 allows XSS via the inline_diff methods i…5.4
- CVE-2021-33514Certain NETGEAR devices are affected by command injection by…9.8
- CVE-2021-33515The submission service in Dovecot before 2.3.15 allows START…4.8
- CVE-2021-33516An issue was discovered in GUPnP before 1.0.7 and 1.1.x and …8.1
- CVE-2021-3352The Software Development Kit in Mitel MiContact Center Busin…9.1
Are you affected by CVE-2021-33511?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
