GHSA-h6rp-mprm-xgcq · Severity: medium · Ecosystem: pip — plone.rest vulnerable to Denial of Service when ++api++ is used many times
plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc. in Plone. Starting in the 2.x branch and prior to versions 2.0.1 and 3.0.1, when the `++api++` traverser is accidentally used multiple times in a url, handling it takes increasingly longer, making the server less responsive. Patches are available in `plone.rest` 2.0.1 and 3.0.1. Series 1.x is not affected. As a workaround, one may redirect `/++api++/++api++` to `/++api++` in one's frontend web server (nginx, Apache).
Conclusion & alert: CVE-2023-42457 is rated Moderate Risk (45.7/100): CVSS High severity, with low exploitation likelihood (EPSS 0.23%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.65% | 0.23% | -0.42% |
| 2 | 2025-11-18 | 0.17% | 0.65% | +0.48% |
| 3 | 2025-04-15 | — | 0.17% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-h6rp-mprm-xgcq · Severity: medium · Ecosystem: pip — plone.rest vulnerable to Denial of Service when ++api++ is used many times
| URL | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2023/09/22/2 | Mailing List Third Party Advisory |
| https://github.com/plone/plone.rest/commit/43b4a7e86206e237e1de5ca3817ed071575882f7 | Patch |
| https://github.com/plone/plone.rest/commit/77846a9842889b24f35e8bedc2e9d461388d3302 | Patch |
| https://github.com/plone/plone.rest/security/advisories/GHSA-h6rp-mprm-xgcq | Vendor Advisory |