PT-2002-1248 · Zope · Zope
Published
2002-04-22
·
Updated
2022-04-30
·
CVE-2002-0170
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Zope versions 2.2.0 through 2.5.1
Description
The issue is related to improper access verification for objects with proxy roles. This could allow certain users to access documents in a way that violates the intended configuration.
Recommendations
For versions 2.2.0 through 2.5.1, update to a version that properly verifies access for objects with proxy roles to prevent unauthorized access.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zope