{"id":"CVE-2011-3587","aliases":["PYSEC-2026-1067"],"url":"https://o3.security/vulnerability/CVE-2011-3587","summary":"Zope Command Execution Vulnerability","details":"Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the `p_` class in `OFS/misc_.py` and the use of Python modules.","published":"2022-05-17T05:37:39Z","modified":"2026-07-07T11:56:24.512524994Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"PyPI","name":"zope2","fixedVersion":"2.12.20"},{"ecosystem":"PyPI","name":"zope2","fixedVersion":"2.13.10"}],"fix":{"url":"https://github.com/zopefoundation/Zope/commit/491a583d8c6622b80c75917e5017c4bb4b15e477","label":"zopefoundation/Zope@491a583"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-3587"},{"type":"WEB","url":"https://github.com/zopefoundation/Zope/commit/491a583d8c6622b80c75917e5017c4bb4b15e477"},{"type":"WEB","url":"https://github.com/zopefoundation/Zope/commit/6bb2fb3c04a76b00bec9bd7c069733e06fa6ebe9"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=742297"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/products-plonehotfix20110928/PYSEC-2011-26.yaml"},{"type":"PACKAGE","url":"https://github.com/zopefoundation/Zope"},{"type":"WEB","url":"https://web.archive.org/web/20111013043934/http://zope2.zope.org/news/security-vulnerability-announcement-cve-2011-3587"},{"type":"WEB","url":"http://plone.org/products/plone-hotfix/releases/20110928"},{"type":"WEB","url":"http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zip"},{"type":"WEB","url":"http://plone.org/products/plone/security/advisories/20110928"},{"type":"WEB","url":"http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0"},{"type":"WEB","url":"http://zope2.zope.org/news/security-vulnerability-announcement-cve-2011-3587"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T11:56:24.512524994Z"}}