Privilege escalation in Kupu
Privilege escalation in Kupu
Versions affected
- 4.2.7
- 4.2.6
- 4.2.5
- 4.2.4
- 4.2.3
- 4.2.2
- 4.2.1
- 4.2
- 4.1.6
- 4.1.5
- 4.1.4
- 4.1.3
- 4.1.2
- 4.1.1
- 4.1
- 4.0.10
- 4.0.9
- 4.0.8
- 4.0.7
- 4.0.5
- 4.0.4
- 4.0.3
- 4.0.2
- 4.0.1
- 4.0
- 3.3.6
- 3.3.5
- 3.3.4
- 3.3.3
- 3.3.2
- 3.3.1
- 3.3
Vulnerability
An incorrect kupu security declaration would allow any authenticated user to edit kupu settings.
Current status
Kupu has not been supported for a long time. This is a retroactive patch to address old versions of Plone. Patch is only issued in the Hotfix.
Credits
Discovered by
- Richard Mitchell
Fixed by
- Richard Mitchell
Coordinated by
- Plone Security Team