CVE-2024-23054
Critical · CVSS 9.8Plone Docker Official Image — Dependency Confusion / Uncontrolled Search Path Element (npm package squatting leading to RCE)
- CVSS
- 9.8
- nvd
- EPSS
- 1.68%
- 74th pct
- KEV
- No
- Class
- other
- CWE-427, CWE-427
Description
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).
Search profile — drives PoC discovery
Symbols ++plone++static/componentsnpmplone-staticpackage.jsonplone docker image
Keywords CVE-2024-23054Plone Dockerdependency confusionnpm package squatting++plone++static/componentsPlone RCEplone 5.2.13CWE-427uncontrolled search pathplone npm missing package
Versions: 5.2.13 (5221)
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T00:30:39.000Z