CVE-2013-4196
Plone is vulnerable to information exposure via the object manager implementation
5.3
MEDIUM
CVSS 3.1
EPSS 0.32%
Description
The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restrict access to internal methods, which allows remote attackers to obtain sensitive information via a crafted request.
How to fix CVE-2013-4196
To remediate CVE-2013-4196, upgrade the affected package to a fixed version below.
- —upgrade to 4.1.1 or later
- —upgrade to 4.1.1 or later
Is CVE-2013-4196 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 2.1, < 4.1.1
- >= 2.1, < 4.1.1, >= 4.2, < 4.2.6, >= 4.3, < 4.3.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |