Skip to content

[GHSA-984m-rj28-8c6x] Plone unauthorized member addition vulnerability - #9627

Open
nikpivkin wants to merge 1 commit into
nikpivkin/advisory-improvement-9627from
nikpivkin-GHSA-984m-rj28-8c6x
Open

nikpivkin wants to merge 1 commit into
nikpivkin/advisory-improvement-9627from
nikpivkin-GHSA-984m-rj28-8c6x

Conversation

@nikpivkin

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3

Comments
The range of the Products.CMFPlone entry for 3.3 to 4.3 should end at < 4.3.7, not < 4.3.6.

The advisory text says "4.3.0 through 4.3.6", and the Plone entry of the same advisory already ends at <= 4.3.6. The fix commit for the 4.3 branch, plone/Products.CMFPlone@9f0111f, is in tag 4.3.7 and not in tag 4.3.6.

So Products.CMFPlone 4.3.6 is still vulnerable but is outside the current range.

Copilot AI balanced review requested due to automatic review settings September 19, 2026 14:23
@github-actions
github-actions Bot changed the base branch from main to nikpivkin/advisory-improvement-9627 September 19, 2026 14:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The corrected metadata now includes vulnerable version 4.3.6 and agrees with the documented 4.3.7 fix.

Review effort: Balanced
Findings: None

What changed in this PR

Aligns the advisory with the confirmed Products.CMFPlone 4.3.7 fix release.

Changes:

  • Removes the stale < 4.3.6 affected-range override.
  • Removes the CVSS v3 vector and updates the modification timestamp.
File Description
GHSA-984m-rj28-8c6x.json Corrects affected-version metadata and severity data.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@nikpivkin

Copy link
Copy Markdown
Author

The removal of the CVSS_V3 score is not intended. The advisory has both a CVSS 3.1 and a CVSS 4.0 vector, and the form seems to keep only one of them. Please keep CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N. The only change I meant is the range of the Products.CMFPlone entry.

@nikpivkin

Copy link
Copy Markdown
Author

I opened #9628 about the form dropping the CVSS 3.1 vector.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants