id: PYSEC-2014-68 details: Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API. affected: - package: name: products-cmfplone ecosystem: PyPI purl: pkg:pypi/products-cmfplone ranges: - type: ECOSYSTEM events: - introduced: "3.3" - fixed: 4.3.3 versions: - 4.0b1 - "4.1" - 4.1.1 - 4.1.2 - 4.1.3 - 4.1.4 - 4.1.5 - 4.1.6 - 4.1a1 - 4.1a2 - 4.1a3 - 4.1b1 - 4.1b2 - 4.1rc2 - 4.1rc3 - "4.2" - 4.2.0.1 - 4.2.1 - 4.2.1.1 - 4.2.2 - 4.2.3 - 4.2.4 - 4.2.5 - 4.2.6 - 4.2.7 - 4.2a1 - 4.2a2 - 4.2b1 - 4.2b2 - 4.2rc1 - 4.2rc2 - "4.3" - 4.3.1 - 4.3.2 - 4.3a1 - 4.3a2 - 4.3b1 - 4.3b2 - 4.3rc1 references: - type: WEB url: https://plone.org/security/20131210/catalogue-exposure - type: WEB url: http://www.openwall.com/lists/oss-security/2013/12/12/3 - type: WEB url: http://www.openwall.com/lists/oss-security/2013/12/10/15 - type: ADVISORY url: https://github.com/advisories/GHSA-4vr8-r7qr-fpvq aliases: - CVE-2013-7061 - GHSA-4vr8-r7qr-fpvq modified: "2021-07-25T23:34:50.085881Z" published: "2014-05-02T14:55:00Z"