PYSEC-2006-10
Withdrawn 2026-07-09. This finding no longer applies and is kept for reference. It is not used when checking packages.
Details
Withdrawn as duplicate of PYSEC-2006-6. Unspecified vulnerability in PlonePAS in Plone 2.5 and 2.5.1, when anonymous member registration is enabled, allows an attacker to "masquerade as a group."
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/plone
Introduced in:
0No fixed version published yet for plone (pip). Pin to a known-safe version or switch to an alternative.