PT-2002-1713 · Zope · Zope
Published
2002-07-23
·
Updated
2022-04-30
·
CVE-2002-0688
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Zope versions 2.4.0 through 2.5.1
Description
The issue allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes due to the ZCatalog plug-in index support capability.
Recommendations
For versions 2.4.0 through 2.5.1, consider restricting access to the ZCatalog plug-in index to prevent anonymous users and untrusted code from bypassing access restrictions.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zope