The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NPlone
APPPlone5.2.13
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassContainer
Related vulnerabilities
CVE-2021-33509CRITICAL9.9PL ✓same product
Plone: zapis dowolnych plików przez transform ReStructuredText
CVE-2020-35190CRITICAL9.8PL ✓same product
Puste hasło roota w oficjalnych obrazach Docker Plone (Alpine)
CVE-2020-7941CRITICAL9.8PL ✓same product
Privilege escalation w Plone — nadpisywanie treści bez uprawnień zapisu
CVE-2024-22889HIGH7.5same product
Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted o...
CVE-2021-33926HIGH8.8same product
An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1,...