PyPi: Plone.Staticresources

CVE-2015-9251

Transitive

Safety vulnerability ID: 49639

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Jan 18, 2018 Updated at Apr 26, 2024
Scan your Python projects for vulnerabilities →

Advisory

Plone.staticresources 1.3.0 adds jQuery workaround for XSS vulnerability.
https://github.com/plone/plone.staticresources/commit/bcd286de96d1f1431299f603ef273189a58db379

Affected package

plone.staticresources

Latest version: 2.1.14

Static resources for Plone

Affected versions

Fixed versions

Vulnerability changelog

------------------

New features:


- Add figcaption support - https://github.com/plone/mockup/pull/911
[thet] (30)
- Register icon resources & add bootstrap-icons
[agitator] (75)
- Adapt ``pat-plone-modal`` and ``pat-inlinevalidation`` to work with barceloneta LTS.
Add missing ``plone.svg`` icon.
[petschki, agitator] (76)
- Update static resources.
[thet] (82)


Bug fixes:


- Fix buildout and use latest Plone 5.2.
[thet] (51)
- Fix missing styles in plone-datatables bundle.
[agitator] (62)
- Upgrade resources with latest mockup.
[thet] (64)
- Move ``metadata.xml`` from async/registry profile directory to correct location. (65)
- Add jQuery workaround for XSS vulnerability - https://github.com/plone/plone.staticresources/issues/69
[frapell] (69)
- Fix ``pat-querystring`` to set value of RelativeDateWidget correctly when editing
[petschki] (78)
- Hide upgrade profile
[petschki] (83)
- fix syntax in `upgrades/profiles/8/registry.xml`
[petschki] (85)

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

MEDIUM 6.1

CVSS v3 Details

MEDIUM 6.1
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
REQUIRED
Scope (S)
CHANGED
Confidentiality Impact (C)
LOW
Integrity Impact (I)
LOW
Availability Availability (A)
NONE

CVSS v2 Details

MEDIUM 4.3
Access Vector (AV)
NETWORK
Access Complexity (AC)
MEDIUM
Authentication (Au)
NONE
Confidentiality Impact (C)
NONE
Integrity Impact (I)
PARTIAL
Availability Impact (A)
NONE