{"id":"CVE-2011-4030","aliases":["GHSA-pwgm-jvqv-6v8p","PYSEC-2026-897"],"title":"Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable","summary":"Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable","severity":"high","vendor":"plone","product":"plone","ecosystem":"pip","affected":["plone >= 4.0, < 4.0.10","plone >= 4.1, < 4.1.1","plone >= 4.2a1, < 4.2a3"],"patched":["plone 4.0.10","plone 4.1.1","plone 4.2a3"],"published":"2022-05-17","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-pwgm-jvqv-6v8p","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4030"},{"url":"https://github.com/plone/Plone"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/products-plonehotfix20110928/PYSEC-2011-27.yaml"},{"url":"http://plone.org/products/plone-hotfix/releases/20110928"},{"url":"http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zip"},{"url":"http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0"}],"tags":["osv","pip"],"epss":0.01991,"epssPercentile":0.79535,"ingestedAt":"2026-07-08T18:25:52.031Z","slug":"CVE-2011-4030","body":"## Overview\n\nThe CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.\n\n## Affected packages\n\n- `plone >= 4.0, < 4.0.10`\n- `plone >= 4.1, < 4.1.1`\n- `plone >= 4.2a1, < 4.2a3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `plone 4.0.10`\n- `plone 4.1.1`\n- `plone 4.2a3`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}