Vulnerabilities > Plone > Plone > 4.2a1

DATE CVE VULNERABILITY TITLE RISK
2011-10-10 CVE-2011-4030 Permissions, Privileges, and Access Controls vulnerability in Plone Cmfeditions and Plone
The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.
network
plone CWE-264
critical
9.3
2011-10-10 CVE-2011-3587 Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.
network
plone zope
critical
9.3