目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2022-23599— Plone 输入验证错误漏洞

CVSS 4.3 · Medium EPSS 0.75% · P52
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2022-23599の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Cross-site Scripting and Open Redirect in Products.ATContentTypes
ソース: CVE Program / CVE List V5
脆弱性説明
Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products.ATContentTypes prior to version 3.0.6 are vulnerable to reflected cross site scripting and open redirect when an attacker can get a compromised version of the image_view_fullscreen page in a cache, for example in Varnish. The technique is known as cache poisoning. Any later visitor can get redirected when clicking on a link on this page. Usually only anonymous users are affected, but this depends on the user's cache settings. Version 3.0.6 of Products.ATContentTypes has been released with a fix. This version works on Plone 5.2, Python 2 only. As a workaround, make sure the image_view_fullscreen page is not stored in the cache. More information about the vulnerability and cvmitigation measures is available in the GitHub Security Advisory.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Plone 输入验证错误漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Plone是一套基于Zope应用服务器构建的开源内容管理系统(CMS)。 Plone 存在输入验证错误漏洞,攻击者可以在缓存中获取受损版本的 image_view_fullscreen 页面。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
-n/a n/a -

II. CVE-2022-23599の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2022-23599のインテリジェンス情報

登录查看更多情报信息。

CVE-2022-23599 补丁与修复 (1)

CVE-2022-23599 厂商安全公告 (1)

Same Patch Batch · n/a · 2022-01-28 · 154 CVEs total

CVE-2021-234849.8 CRITICALArbitrary File Write via Archive Extraction (Zip Slip)
CVE-2021-444638.1 HIGHEmerson DeltaV Uncontrolled Search Path Element
CVE-2022-229927.8 HIGHCommand Injection Remote Code Execution vulnerability on Western Digital My Cloud devices.
CVE-2021-235587.3 HIGHPrototype Pollution
CVE-2021-315676.8 MEDIUMWordPress Download Monitor plugin <= 4.4.6 - Authenticated Arbitrary File Download vulnera
CVE-2022-227916.6 MEDIUMSYNEL - eharmony Authenticated Blind & Stored XSS
CVE-2021-238636.1 MEDIUMBosch Video Security 跨站脚本漏洞
CVE-2022-217196.1 MEDIUMReflected XSS using reload button in GLPI
CVE-2021-262646.1 MEDIUMEmerson DeltaV Missing Authentication for Critical Function
CVE-2022-217215.9 MEDIUMDOS Vulnerability in next.js
CVE-2021-237605.6 MEDIUMPrototype Pollution
CVE-2022-227905.6 MEDIUMSYNEL - eharmony Directory Traversal
CVE-2022-217204.9 MEDIUMSQL injection using custom CSS administration form in GLPI
CVE-2022-239794.8 MEDIUMWordPress Ultimate Reviews plugin <= 3.0.15 - Authenticated Stored Cross-Site Scripting (X
CVE-2021-403403.7 LOWOWASP Related Vulnerabilities in Hitachi Energy’s LinkOne Product
CVE-2021-403393.7 LOWOWASP Related Vulnerabilities in Hitachi Energy’s LinkOne Product
CVE-2021-403383.7 LOWOWASP Related Vulnerabilities in Hitachi Energy’s LinkOne Product
CVE-2021-44377Reolink Rlc-410W 输入验证错误漏洞
CVE-2021-44371Reolink Rlc-410W 输入验证错误漏洞
CVE-2021-44374Reolink Rlc-410W 输入验证错误漏洞

Showing 20 of 154 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2022-23599へのコメント

まだコメントはありません


コメントを残す