CVE-2012-6661

medium
Published 2018-07-23 · Modified 2023-11-08
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2
5.0
VIR risk
5.0

Description

Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://plone.org/products/plone/security/advisories/20121106/24

Package impact

EcosystemPackageVulnerableFixed
python PyPIzope2<2.13.192.13.19
python PyPIplone>=3.2.2,<4.2.34.2.3
python PyPIplone>=4.3a1,<4.3b14.3b1
python PyPIplone>=4.3a0,<4.3b14.2.3

Application impact

VendorProductVersionsFixed
ploneplone{"endIncluding":"4.2.2"}
ploneplone1.0
ploneplone1.0.1
ploneplone1.0.2
ploneplone1.0.3
ploneplone1.0.4
ploneplone1.0.5
ploneplone1.0.6
ploneplone2.0
ploneplone2.0.1
ploneplone2.0.2
ploneplone2.0.3
ploneplone2.0.4
ploneplone2.0.5
ploneplone2.1
ploneplone2.1.1
ploneplone2.1.2
ploneplone2.1.3
ploneplone2.1.4
ploneplone2.5
ploneplone2.5.1
ploneplone2.5.2
ploneplone2.5.3
ploneplone2.5.4
ploneplone2.5.5
ploneplone3.0
ploneplone3.0.1
ploneplone3.0.2
ploneplone3.0.3
ploneplone3.0.4
ploneplone3.0.5
ploneplone3.0.6
ploneplone3.1
ploneplone3.1.1
ploneplone3.1.2
ploneplone3.1.3
ploneplone3.1.4
ploneplone3.1.5.1
ploneplone3.1.6
ploneplone3.1.7
ploneplone3.2
ploneplone3.2.1
ploneplone3.2.2
ploneplone3.2.3
ploneplone3.3
ploneplone3.3.1
ploneplone3.3.2
ploneplone3.3.3
ploneplone3.3.4
ploneplone3.3.5
ploneplone4.0
ploneplone4.0.1
ploneplone4.0.2
ploneplone4.0.3
ploneplone4.0.4
ploneplone4.0.5
ploneplone4.0.6.1
ploneplone4.1
ploneplone4.1.4
ploneplone4.1.5
ploneplone4.1.6
ploneplone4.2
ploneplone4.2.1
ploneplone4.3
zopezope{"endIncluding":"2.13.18"}

References

CWEs

CWE-310

Verify integrity in audit chain (admin only). AS-IS.