PT-2002-1713 · Zope · Zope
Publicado
2002-07-23
·
Atualizado
2022-04-30
·
CVE-2002-0688
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Zope versions 2.4.0 through 2.5.1
Description
The issue allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes due to the ZCatalog plug-in index support capability.
Recommendations
For versions 2.4.0 through 2.5.1, consider restricting access to the ZCatalog plug-in index to prevent anonymous users and untrusted code from bypassing access restrictions.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Zope