CVE-2010-2422 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2422): Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 through 3.3.4 before hotfix 20100612 allows remote attackers to inject arbitrary web script or HTML via the safe_html transform.
Closing as INVALID, the package is masked. No need glsa here because is XSS.
(In reply to comment #1) > Closing as INVALID, the package is masked. No need glsa here because is XSS. Restored since it comes out from the tree.
Package is gone from tree for a long time, and this is XSS, closing as noglsa