{"id":"CVE-2011-4030","aliases":["PYSEC-2026-897"],"url":"https://o3.security/vulnerability/CVE-2011-4030","summary":"Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable","details":"The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.","published":"2022-05-17T05:37:14Z","modified":"2026-07-07T11:56:16.177194408Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"plone","fixedVersion":"4.0.10"},{"ecosystem":"PyPI","name":"plone","fixedVersion":"4.1.1"},{"ecosystem":"PyPI","name":"plone","fixedVersion":"4.2a3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4030"},{"type":"PACKAGE","url":"https://github.com/plone/Plone"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/products-plonehotfix20110928/PYSEC-2011-27.yaml"},{"type":"WEB","url":"http://plone.org/products/plone-hotfix/releases/20110928"},{"type":"WEB","url":"http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zip"},{"type":"WEB","url":"http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T11:56:16.177194408Z"}}