{ "info": { "author": "Plone security team", "author_email": "security@plone.org", "bugtrack_url": null, "classifiers": [ "Framework :: Plone", "Framework :: Zope2", "Programming Language :: Python" ], "description": "Plone Hotfix package, 2011-10-04\n********************************\n\nThis hotfix fixes the following vulnerabilities:\n\n* A vulnerability in CMFEditions where KwAsAttributes classes were publishable,\n exposing sub-objects to anonymous access. This vulnerability is found in\n CMFEditions 2.0a1 and up. CMFEditions 1.x and before are not vulnerable.\n\n* Zope vulnerability `CVE 2011-3587`_. This vulnerability is found in Zope\n 2.12.x and 2.13.x. Zope 2.11 and before are not vulnerable.\n\n This Plone Hotfix applies the same fix as Products.Zope_Hotfix_CVE_2011_3587\n and can co-exist with that patch.\n\n.. _`CVE 2011-3587`: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2011-3587\n\n\nThis hotfix is supported on Plone 4.0 - 4.0.9, 4.1 and 4.2. Older versions\nof Plone (3.3.x and below) are not affected by the vulnerabilities and are not\nsupported by this patch.\n\nThe fixes included here will be incorporated into subsequent releases of Plone,\nso Plone 4.0.10, 4.1.1, 4.2a3 and greater should not require this hotfix.\n\n\nInstallation\n============\n\nInstallation instructions can be found at\nhttp://plone.org/products/plone-hotfix/releases/20110928\n\n\nChangelog\n=========\n\n1.1 (2011-10-04)\n----------------\n\n- Fix URLs in the readme and setup.py.\n [mj]\n\n1.0 (2011-10-04)\n----------------\n\n- Initial release\n [Plone security team]", "description_content_type": null, "docs_url": null, "download_url": "UNKNOWN", "downloads": { "last_day": -1, "last_month": -1, "last_week": -1 }, "home_page": "http://plone.org/products/plone-hotfix/releases/20110928", "keywords": "security hotfix patch", "license": "GPL", "maintainer": null, "maintainer_email": null, "name": "Products.PloneHotfix20110928", "package_url": "https://pypi.org/project/Products.PloneHotfix20110928/", "platform": "UNKNOWN", "project_url": "https://pypi.org/project/Products.PloneHotfix20110928/", "project_urls": { "Download": "UNKNOWN", "Homepage": "http://plone.org/products/plone-hotfix/releases/20110928" }, "release_url": "https://pypi.org/project/Products.PloneHotfix20110928/1.1/", "requires_dist": null, "requires_python": null, "summary": "Plone critical security hotfix addressing vulnerabilities in Zope and CMFEditions", "version": "1.1" }, "last_serial": 658926, "releases": { "1.0": [ { "comment_text": "", "digests": { "md5": "c794acedfc973018310f6ac111d7d8e4", "sha256": "0ff27dc4d4befd31c2891f852bdd5b747d1b2197e25a753212b5e0e0776262eb" }, "downloads": -1, "filename": "Products.PloneHotfix20110928-1.0.zip", "has_sig": false, "md5_digest": "c794acedfc973018310f6ac111d7d8e4", "packagetype": "sdist", "python_version": "source", "requires_python": null, "size": 6837, "upload_time": "2011-10-04T17:04:40", "url": "https://files.pythonhosted.org/packages/37/3f/eb0058f29ab4d135b0bd5e66dbe09e1ba27eac306b5a8d9859f7db6cd8a9/Products.PloneHotfix20110928-1.0.zip" } ], "1.1": [ { "comment_text": "", "digests": { "md5": "b7bb70dcfdaa4d023b83e0d66629f1e5", "sha256": "ba793c9f2018ca71e29b21bdabab89587a5af00d38c08546cf16e551971c49e4" }, "downloads": -1, "filename": "Products.PloneHotfix20110928-1.1.zip", "has_sig": false, "md5_digest": "b7bb70dcfdaa4d023b83e0d66629f1e5", "packagetype": "sdist", "python_version": "source", "requires_python": null, "size": 6931, "upload_time": "2011-10-04T17:23:16", "url": "https://files.pythonhosted.org/packages/b4/84/af368672fcb072b6576e9121e13c04b97f3509e74d5f6ebb8d8d948cd9e3/Products.PloneHotfix20110928-1.1.zip" } ] }, "urls": [ { "comment_text": "", "digests": { "md5": "b7bb70dcfdaa4d023b83e0d66629f1e5", "sha256": "ba793c9f2018ca71e29b21bdabab89587a5af00d38c08546cf16e551971c49e4" }, "downloads": -1, "filename": "Products.PloneHotfix20110928-1.1.zip", "has_sig": false, "md5_digest": "b7bb70dcfdaa4d023b83e0d66629f1e5", "packagetype": "sdist", "python_version": "source", "requires_python": null, "size": 6931, "upload_time": "2011-10-04T17:23:16", "url": "https://files.pythonhosted.org/packages/b4/84/af368672fcb072b6576e9121e13c04b97f3509e74d5f6ebb8d8d948cd9e3/Products.PloneHotfix20110928-1.1.zip" } ] }