6.5
CVSSv3

CVE-2017-1000483

Published: 03/01/2018 Updated: 03/10/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.

Vulnerable Product Search on Vulmon Subscribe to Product

plone plone 5.0.6

plone plone 5.0.5

plone plone 5.0.4

plone plone 5.0.3

plone plone 5.0.2

plone plone 4.3.4

plone plone 4.3.3

plone plone 4.3.2

plone plone 4.3.1

plone plone 4.1.2

plone plone 4.1.1

plone plone 4.1

plone plone 4.0.10

plone plone 3.3.2

plone plone 3.3.1

plone plone 3.3

plone plone 2.5.5

plone plone 5.1

plone plone 4.3.12

plone plone 4.3.11

plone plone 4.3.10

plone plone 4.3.9

plone plone 4.2.3

plone plone 4.2.2

plone plone 4.2.1

plone plone 4.2

plone plone 4.0.4

plone plone 4.0.3

plone plone 4.0.2

plone plone 4.0.1

plone plone 5.0

plone plone 5.0.7

plone plone 4.3.14

plone plone 4.3.8

plone plone 4.3.6

plone plone 4.2.7

plone plone 4.2.5

plone plone 4.1.5

plone plone 4.1.3

plone plone 4.0.9

plone plone 4.0.7

plone plone 3.3.6

plone plone 3.3.4

plone plone 5.0.8

plone plone 5.0.1

plone plone 4.3.15

plone plone 4.3.7

plone plone 4.3.5

plone plone 4.3

plone plone 4.2.6

plone plone 4.2.4

plone plone 4.1.6

plone plone 4.1.4

plone plone 4.0.8

plone plone 4.0.5

plone plone 4.0

plone plone 3.3.5

plone plone 3.3.3

plone plone 5.0.9

Vendor Advisories

Accessing private content via strformat in through-the-web templates and scripts in Plone 25-51rc1 This improves an earlier hotfix Since the format method was introduced in Python 26, this part of the hotfix is only relevant for Plone 4 and 5 ...