Privilege escalation in Kupu

Privilege escalation in Kupu

Versions affected

  • 4.2.7
  • 4.2.6
  • 4.2.5
  • 4.2.4
  • 4.2.3
  • 4.2.2
  • 4.2.1
  • 4.2
  • 4.1.6
  • 4.1.5
  • 4.1.4
  • 4.1.3
  • 4.1.2
  • 4.1.1
  • 4.1
  • 4.0.10
  • 4.0.9
  • 4.0.8
  • 4.0.7
  • 4.0.5
  • 4.0.4
  • 4.0.3
  • 4.0.2
  • 4.0.1
  • 4.0
  • 3.3.6
  • 3.3.5
  • 3.3.4
  • 3.3.3
  • 3.3.2
  • 3.3.1
  • 3.3

Vulnerability

An incorrect kupu security declaration would allow any authenticated user to edit kupu settings.

Current status

Kupu has not been supported for a long time. This is a retroactive patch to address old versions of Plone. Patch is only issued in the Hotfix.

Credits

Discovered by

  • Richard Mitchell

Fixed by

  • Richard Mitchell

Coordinated by

  • Plone Security Team