Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file object for unspecified documentation which is initialized in class scope.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://plone.org/security/20131210/path-leak | vendor advisory |
http://www.openwall.com/lists/oss-security/2013/12/12/3 | mailing list |
http://www.openwall.com/lists/oss-security/2013/12/10/15 | mailing list |