Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2024-23756

Disclosure Date: February 08, 2024 (last updated February 16, 2024)
The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.
Attacker Value
Unknown

CVE-2024-23054

Disclosure Date: February 05, 2024 (last updated February 14, 2024)
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).
Attacker Value
Unknown

CVE-2024-23055

Disclosure Date: January 25, 2024 (last updated February 03, 2024)
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.