LOW 3.1 PyPI

Plone Denial of Service vulnerability via decompressing large zip archives

GHSA-xfjq-9rxq-ph6m · CVE-2013-4199 · PYSEC-2014-63

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

(1) cb_decode.py and (2) linkintegrity.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users to cause a denial of service (resource consumption) via a large zip archive, which is expanded (decompressed).

Ready to move

Start Securing

Free, no credit card | First findings in minutes