—
PYSEC-2020-85
Quick fix
PYSEC-2020-85 — plone: upgrade to the fixed version with the command below.
pip install --upgrade 'plone>=5.2.2'Details
An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://plone.org/security/hotfix/20200121[WEB]
- https://plone.org/security/hotfix/20200121/an-open-redirection-on-the-login-form-and-possibly-other-places[WEB]
- https://www.openwall.com/lists/oss-security/2020/01/22/1[WEB]
- http://www.openwall.com/lists/oss-security/2020/01/24/1[WEB]
- https://github.com/advisories/GHSA-82j9-wfcf-9v2h[ADVISORY]