---
id: CVE-2011-4030
aliases:
  - GHSA-pwgm-jvqv-6v8p
  - PYSEC-2026-897
title: >-
  Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes
  classes were publishable
summary: >-
  Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes
  classes were publishable
severity: high
vendor: plone
product: plone
ecosystem: pip
affected:
  - 'plone >= 4.0, < 4.0.10'
  - 'plone >= 4.1, < 4.1.1'
  - 'plone >= 4.2a1, < 4.2a3'
patched:
  - plone 4.0.10
  - plone 4.1.1
  - plone 4.2a3
published: '2022-05-17'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-pwgm-jvqv-6v8p'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2011-4030'
  - url: 'https://github.com/plone/Plone'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/products-plonehotfix20110928/PYSEC-2011-27.yaml
  - url: 'http://plone.org/products/plone-hotfix/releases/20110928'
  - url: >-
      http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zip
  - url: 'http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0'
tags:
  - osv
  - pip
epss: 0.01991
epssPercentile: 0.79535
ingestedAt: '2026-07-08T18:25:52.031Z'
---

## Overview

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.

## Affected packages

- `plone >= 4.0, < 4.0.10`
- `plone >= 4.1, < 4.1.1`
- `plone >= 4.2a1, < 4.2a3`

## Remediation

Upgrade to a patched release:

- `plone 4.0.10`
- `plone 4.1.1`
- `plone 4.2a3`
