{"id":"GHSA-pwgm-jvqv-6v8p","summary":"Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable","details":"The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.","aliases":["CVE-2011-4030","PYSEC-2026-897"],"modified":"2026-07-07T11:56:16.177194408Z","published":"2022-05-17T05:37:14Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-14T17:25:59Z","nvd_published_at":"2011-10-10T10:55:00Z","cwe_ids":[]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4030"},{"type":"PACKAGE","url":"https://github.com/plone/Plone"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/products-plonehotfix20110928/PYSEC-2011-27.yaml"},{"type":"WEB","url":"http://plone.org/products/plone-hotfix/releases/20110928"},{"type":"WEB","url":"http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zip"},{"type":"WEB","url":"http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0"}],"affected":[{"package":{"name":"plone","ecosystem":"PyPI","purl":"pkg:pypi/plone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0"},{"fixed":"4.0.10"}]}],"versions":["4.0","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","4.0.7","4.0.8","4.0.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 4.0.9","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-pwgm-jvqv-6v8p/GHSA-pwgm-jvqv-6v8p.json"}},{"package":{"name":"plone","ecosystem":"PyPI","purl":"pkg:pypi/plone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1"},{"fixed":"4.1.1"}]}],"versions":["4.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-pwgm-jvqv-6v8p/GHSA-pwgm-jvqv-6v8p.json"}},{"package":{"name":"plone","ecosystem":"PyPI","purl":"pkg:pypi/plone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.2a1"},{"fixed":"4.2a3"}]}],"versions":["4.2a1","4.2a2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-pwgm-jvqv-6v8p/GHSA-pwgm-jvqv-6v8p.json","last_known_affected_version_range":"\u003c= 4.2a2"}}],"schema_version":"1.9.0"}