Loading
Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.
Use CWE-276, Plone vendor hub and Plone product page to widen CVE-2024-22889 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-33509, CVE-2021-33926 and CVE-2024-23756 for nearby disclosures in the same product family.