Plone CMS Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition) Vulnerability - CVE-2012-5507
AccessControl/AuthEncoding.py in Zope before 2.13.19 as used in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.