This is a pre-announcement on behalf of the Plone/Zope Security Team.
This Tuesday, June 23, the Plone/Zope Security Team plans to release several packages and publish security announcements. The vulnerabilities include Remote Code Execution and Denial of Service. In all cases, an attacker already needs to be able to add content or portlets.
We usually don't do pre-announcements anymore, but these are several high severity issues, so we make an exception, and give at least a small period of warning.
In all, about five to six packages are involved. We are preparing fixes for all supported Plone minor versions: 6.0, 6.1, 6.2.
We expect to do this around 1300 UTC. With that many packages, and two to three branches per package, it will take a while though.
The new package versions will be made available in Plone bugfix releases 6.1.5 and 6.2.1. This can take a few days more though, so we can first fix any problems if they surface during production use.
What can I do already?
Make sure you are on the latest bugfix release within a Plone minor version. We only test the fixes there, though they may work on older versions.
For some of the vulnerabilities workarounds will be available, which involves restricting permissions. Check that you can get to the Security tab in the Zope Management Interface.