Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 325609 (CVE-2010-2422) - net-zope/plone: XSS (CVE-2010-2422)
Summary: net-zope/plone: XSS (CVE-2010-2422)
Status: RESOLVED FIXED
Alias: CVE-2010-2422
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor
Assignee: Gentoo Security
URL: http://plone.org/products/plone/secur...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-06-25 21:32 UTC by Stefan Behte (RETIRED)
Modified: 2013-10-17 08:02 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2010-06-25 21:32:21 UTC
CVE-2010-2422 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2422):
  Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone
  2.1 through 3.3.4 before hotfix 20100612 allows remote attackers to
  inject arbitrary web script or HTML via the safe_html transform.
Comment 1 Agostino Sarubbo gentoo-dev 2011-10-11 14:23:35 UTC
Closing as INVALID, the package is masked. No need glsa here because is XSS.
Comment 2 Agostino Sarubbo gentoo-dev 2011-10-11 16:30:29 UTC
(In reply to comment #1)
> Closing as INVALID, the package is masked. No need glsa here because is XSS.

Restored since it comes out from the tree.
Comment 3 Sergey Popov (RETIRED) gentoo-dev 2013-10-17 08:02:23 UTC
Package is gone from tree for a long time, and this is XSS, closing as noglsa