Hi all,

Two low-impact security issues have been identified in 
Products.PluggableAuthService:

- an information disclosure issue involving the ZODB Role Manager plugin. See 
https://github.com/zopefoundation/Products.PluggableAuthService/security/advisories/GHSA-p75f-g7gx-2r7p
 for details.

- an open redirect issue in the Cookie Auth Helper. See 
https://github.com/zopefoundation/Products.PluggableAuthService/security/advisories/GHSA-p44j-xrqg-4xrr
 for details.

Both issues are mitigated by updating to Products.PluggableAuthService version 
2.6.1 or higher. The Plone release managers will apply this update with Plone 
bugfix releases they are planning to publish within the next few days.

jens


Attachment: signature.asc
Description: Message signed with OpenPGP

_______________________________________________
Zope-Announce maillist  -  Zope-Announce@zope.org
https://mail.zope.org/mailman/listinfo/zope-announce

  Zope-Announce for Announcements only - no discussions

(Related lists -
 Users: https://mail.zope.org/mailman/listinfo/zope
 Developers: https://mail.zope.org/mailman/listinfo/zope-dev )

Reply via email to