GHSA-hjp5-hv33-q58g

Suggest an improvement
Source
https://github.com/advisories/GHSA-hjp5-hv33-q58g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hjp5-hv33-q58g/GHSA-hjp5-hv33-q58g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hjp5-hv33-q58g
Aliases
Published
2022-05-01T23:39:47Z
Modified
2026-07-06T08:11:19Z
Summary
Plone credentials stored in session cookie
Details

Plone CMS 3.1.x uses invariant data (a client username and a server secret) when calculating an HMAC-SHA1 value for an authentication cookie, which makes it easier for remote attackers to gain permanent access to an account by sniffing the network.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-09-22T23:41:41Z",
    "nvd_published_at":  "2008-03-20T00:44:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

PyPI / plone

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.1.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hjp5-hv33-q58g/GHSA-hjp5-hv33-q58g.json"