#5958 plone security vulnerability
Closed: Fixed None Opened 9 years ago by sparks.

plone has an important CVE against the current version shipped in epel-5. The package is orphaned. Can we remove the package from EPEL 5 or push an update > 4.0?

BTW, this plone appears to be being shipped in RHEL 5.7.

Bug: https://bugzilla.redhat.com/show_bug.cgi?id=692662
CVE: https://bugzilla.redhat.com/show_bug.cgi?id=676961


It is retired in EPEL5 now and I untagged all builds in dist-5E-epel, so it should not be shipped after the next compose.

Metadata Update from @sparks:
- Issue set to the milestone: Fedora 20 Final

7 years ago

Login to comment on this ticket.

Metadata