Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.Referenceshttps://plone.org/security/20131210/catalogue-exposurehttp://www.openwall.com/lists/oss-security/2013/12/12/3http://www.openwall.com/lists/oss-security/2013/12/10/15