7 Kusagadzikana muPlone Content Management System

Zvemahara zvemukati manejimendi system ndege, yakanyorwa muPython uchishandisa Zope application server, rakabudiswa zvigamba nekubvisa 7 kushaya simba (CVE zviziviso hazvisati zvapihwa). Matambudziko anokanganisa zvese zvazvino zvaburitswa zvePlone, kusanganisira kuburitswa kwakaburitswa mazuva mashoma apfuura 5.2.1. Nyaya dzakarongwa kuti dzigadziriswe mune ramangwana rekuburitswa kwePlone 4.3.20, 5.1.7 uye 5.2.2, isati yadhindwa iyo yainokurudzirwa kushandisa. hotfix.

Kuzivikanwa kusakanganiswa (zvizhinji hazvisati zvaburitswa):

  • Kukwidziridzwa kweropafadzo kuburikidza nekugadzirisa kweRest API (inoonekwa chete kana plone.restapi yagoneswa);
  • Kutsiviwa kweSQL kodhi nekuda kwekusakwana kutiza kweSQL inovaka muDTML uye zvinhu zvekubatanidza kuDBMS (dambudziko rakanangana ne. Zope uye inoonekwa mune mamwe maapplication akavakirwa pazviri);
  • Iko kugona kunyora zvakare zvirimo kuburikidza nemanipulations nePUT nzira pasina kuve nekodzero dzekunyora;
  • Vhura redirect mune iyo login fomu;
  • Mikana yekutumira zvinongedzo zvekunze zvinongedzo nekupfuura iyo isURLInPortal cheki;
  • Pasiwedhi simba cheki inokundikana mune dzimwe nguva;
  • Muchinjikwa-saiti scripting (XSS) kuburikidza nekodhi inotsiva mundima yezita.

Source: opennet.ru