Security Advisory

CVE-2021-33511

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-05-21 21:32:24
Last updated 2024-08-03 23:50:42
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.