—
PYSEC-2014-62
Quick fix
PYSEC-2014-62 — plone: upgrade to the fixed version with the command below.
pip install --upgrade 'plone>=4.1.1'Details
mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to bypass the prohibition on password changes via the forgotten password email functionality.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://bugzilla.redhat.com/show_bug.cgi?id=978480[REPORT]
- http://seclists.org/oss-sec/2013/q3/261[WEB]
- http://plone.org/products/plone-hotfix/releases/20130618[WEB]
- http://plone.org/products/plone/security/advisories/20130618-announcement[ADVISORY]
- https://github.com/advisories/GHSA-qjxf-6pr8-j87v[ADVISORY]