{"id":"GHSA-p6h9-hpcg-c6gm","summary":"High severity vulnerability that affects Plone and Zope2","details":"Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) PloneHotfix20110720 for Plone 3.x allows attackers to gain privileges via unspecified vectors, related to a \"highly serious vulnerability.\" NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-0720.","aliases":["CVE-2011-2528","PYSEC-2011-25","PYSEC-2026-764"],"modified":"2026-07-09T16:56:34.756904405Z","published":"2018-07-23T19:52:02Z","database_specific":{"github_reviewed_at":"2020-06-16T21:48:24Z","nvd_published_at":"2011-07-19T20:55:01Z","cwe_ids":[],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-2528"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=718824"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2011-25.yaml"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2011-32.yaml"},{"type":"WEB","url":"https://mail.zope.org/pipermail/zope-announce/2011-June/002260.html"},{"type":"WEB","url":"https://plone.org/products/plone-hotfix/releases/20110622"},{"type":"WEB","url":"https://plone.org/products/plone/security/advisories/20110622"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2011/07/04/6"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2011/07/12/9"},{"type":"WEB","url":"http://plone.org/products/plone-hotfix/releases/20110622"},{"type":"WEB","url":"http://plone.org/products/plone/security/advisories/20110622"},{"type":"WEB","url":"http://secunia.com/advisories/45056"},{"type":"WEB","url":"http://secunia.com/advisories/45111"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/07/04/6"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/07/12/9"}],"affected":[{"package":{"name":"plone","ecosystem":"PyPI","purl":"pkg:pypi/plone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.3.2"},{"fixed":"3.3.6"}]}],"versions":["3.3.2","3.3.3","3.3.4","3.3.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-p6h9-hpcg-c6gm/GHSA-p6h9-hpcg-c6gm.json"}},{"package":{"name":"zope2","ecosystem":"PyPI","purl":"pkg:pypi/zope2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.12.0"},{"fixed":"2.12.19"}]}],"versions":["2.12.0","2.12.1","2.12.10","2.12.11","2.12.12","2.12.13","2.12.14","2.12.15","2.12.16","2.12.17","2.12.18","2.12.2","2.12.3","2.12.4","2.12.5","2.12.6","2.12.7","2.12.8","2.12.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-p6h9-hpcg-c6gm/GHSA-p6h9-hpcg-c6gm.json"}},{"package":{"name":"zope2","ecosystem":"PyPI","purl":"pkg:pypi/zope2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.13.0"},{"fixed":"2.13.8"}]}],"versions":["2.13.0","2.13.1","2.13.2","2.13.3","2.13.4","2.13.5","2.13.6","2.13.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-p6h9-hpcg-c6gm/GHSA-p6h9-hpcg-c6gm.json"}}],"schema_version":"1.9.0"}