VDB
Sign up
—

PYSEC-2017-53

Quick fix

PYSEC-2017-53 — plone: upgrade to the fixed version with the command below.

pip install --upgrade 'plone>=3da710a2cd68587f0bf34f2e7ea1167d6eeee087'

Details

Cross-site scripting (XSS) vulnerability in Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.x before 4.3.7, and 5.0rc1.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/plone
Introduced in: 0Fixed in: 3da710a2cd68587f0bf34f2e7ea1167d6eeee087
Fixpip install --upgrade 'plone>=3da710a2cd68587f0bf34f2e7ea1167d6eeee087'

References