From 8c994f3a9c8e39976407391677ccf3a84e9da7ae Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 21 Oct 2024 05:14:13 +0000 Subject: [PATCH] Publish GHSA-3qpr-7rmg-73v8 --- .../2018/07/GHSA-3qpr-7rmg-73v8/GHSA-3qpr-7rmg-73v8.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2018/07/GHSA-3qpr-7rmg-73v8/GHSA-3qpr-7rmg-73v8.json b/advisories/github-reviewed/2018/07/GHSA-3qpr-7rmg-73v8/GHSA-3qpr-7rmg-73v8.json index f70e36150df..bed7a04c33d 100644 --- a/advisories/github-reviewed/2018/07/GHSA-3qpr-7rmg-73v8/GHSA-3qpr-7rmg-73v8.json +++ b/advisories/github-reviewed/2018/07/GHSA-3qpr-7rmg-73v8/GHSA-3qpr-7rmg-73v8.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3qpr-7rmg-73v8", - "modified": "2024-10-11T21:23:02Z", + "modified": "2024-10-11T21:23:40Z", "published": "2018-07-23T19:51:02Z", "aliases": [ "CVE-2012-5507" ], - "summary": "Moderate severity vulnerability that affects Plone and Zope2", + "summary": "Plone and Zope2 affected by Race Condition", "details": "AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.", "severity": [ {