Security Advisory

CVE-2021-33511

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-05-21 21:32:24
Last updated 2024-08-03 23:50:42
Assigner mitre
State PUBLISHED

Description

Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.