CVE-2021-33926
published 2023-02-17CVE-2021-33926: An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1…
PriorityP347high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.00%
58.6th percentile
An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.10, 5.0.1, 5.0, 4.3.9, 4.3.8, 4.3.7, 4.3.6, 4.3.5, 4.3.4, 4.3.3, 4.3.20, 4 allows attacker to access sensitive information via the RSS feed protlet.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
| plone | plone | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2021-33926: An issue in Plone CMS v
osv·2023-02-17
CVE-2021-33926 CVE-2021-33926: An issue in Plone CMS v
An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.10, 5.0.1, 5.0, 4.3.9, 4.3.8, 4.3.7, 4.3.6, 4.3.5, 4.3.4, 4.3.3, 4.3.20, 4 allows attacker to access sensitive information via the RSS feed protlet.
OSV
Server-Side Request Forgery in Plone CMS
osv·2023-02-17
CVE-2021-33926 [HIGH] Server-Side Request Forgery in Plone CMS
Server-Side Request Forgery in Plone CMS
An issue in Plone CMS allows attacker to access sensitive information via the RSS feed protlet.
GHSA
Server-Side Request Forgery in Plone CMS
ghsa·2023-02-17
CVE-2021-33926 [HIGH] CWE-918 Server-Side Request Forgery in Plone CMS
Server-Side Request Forgery in Plone CMS
An issue in Plone CMS allows attacker to access sensitive information via the RSS feed protlet.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/s-kustm/Subodh/blob/master/Plone%205.2.4%20Vulnerable%20to%20bilend%20SSRF.pdfhttps://plone.org/security/hotfix/20210518https://plone.org/security/hotfix/20210518/blind-ssrf-via-feedparser-accessing-an-internal-urlhttps://github.com/s-kustm/Subodh/blob/master/Plone%205.2.4%20Vulnerable%20to%20bilend%20SSRF.pdfhttps://plone.org/security/hotfix/20210518https://plone.org/security/hotfix/20210518/blind-ssrf-via-feedparser-accessing-an-internal-url
2023-02-17
Published