Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.
References
| Link | Resource |
|---|---|
| https://github.com/shenhav12/CVE-2024-22889-Plone-v6.0.9 | Third Party Advisory |
| https://github.com/shenhav12/CVE-2024-22889-Plone-v6.0.9 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-03-06 00:15
Updated : 2025-01-21 16:53
NVD link : CVE-2024-22889
Mitre link : CVE-2024-22889
CVE.ORG link : CVE-2024-22889
JSON object : View
Products Affected
plone
- plone
CWE
CWE-276
Incorrect Default Permissions
