{"id":"PYSEC-2026-897","summary":"Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable","details":"The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.","aliases":["CVE-2011-4030","GHSA-pwgm-jvqv-6v8p"],"modified":"2026-07-07T11:45:17.337877161Z","published":"2026-07-06T08:03:27.332968Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4030"},{"type":"PACKAGE","url":"https://github.com/plone/Plone"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/products-plonehotfix20110928/PYSEC-2011-27.yaml"},{"type":"WEB","url":"http://plone.org/products/plone-hotfix/releases/20110928"},{"type":"WEB","url":"http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zip"},{"type":"WEB","url":"http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0"},{"type":"PACKAGE","url":"https://pypi.org/project/plone"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pwgm-jvqv-6v8p"}],"affected":[{"package":{"name":"plone","ecosystem":"PyPI","purl":"pkg:pypi/plone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0"},{"fixed":"4.0.10"},{"introduced":"4.1"},{"fixed":"4.1.1"},{"introduced":"4.2a1"},{"fixed":"4.2a3"}]}],"versions":["4.0","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","4.0.7","4.0.8","4.0.9","4.1","4.2a1","4.2a2"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/plone/PYSEC-2026-897.yaml"}}],"schema_version":"1.7.5"}