HIGH8.8
PYSEC-2026-2889
Plone Privilege Escallation
Quick fix
PYSEC-2026-2889 — plone-restapi: upgrade to the fixed version with the command below.
pip install --upgrade 'plone-restapi>=6.2.1'Details
plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-7938[ADVISORY]
- https://github.com/plone/plone.restapi/issues/857[WEB]
- https://github.com/plone/plone.restapi/pull/859[WEB]
- https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2020-87.yaml[WEB]
- https://plone.org/security/hotfix/20200121[WEB]
- https://plone.org/security/hotfix/20200121/privilege-escalation-when-plone-restapi-is-installed[WEB]
- https://www.openwall.com/lists/oss-security/2020/01/22/1[WEB]
- http://www.openwall.com/lists/oss-security/2020/01/24/1[WEB]
- https://pypi.org/project/plone-restapi[PACKAGE]
- https://github.com/advisories/GHSA-cjg3-q24h-9qwf[ADVISORY]