queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass caching and cause a denial of service via a crafted request to a collection.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.