CVE-2007-5741
zope-cmfplone - arbitrary code
9.8
CRITICAL
CVSS 3.1
EPSS 3.6%
Description
Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled objects for the (1) statusmessages or (2) linkintegrity module, which the module unpickles and executes.
How to fix CVE-2007-5741
To remediate CVE-2007-5741, upgrade the affected package to a fixed version below.
- Debian/zope-cmfplone—upgrade to 2.5.1-4etch1 or later
- —upgrade to 2.5.1-4etch2 or later
- —upgrade to 2.5.5 or later
- —upgrade to 2.5.5 or later
Is CVE-2007-5741 being exploited?
Low — EPSS is 3.6%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 2.5.1-4etch1
- from 0, < 2.5.1-4etch2
- >= 2.5, < 2.5.5
- >= 2.5, < 2.5.5
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |