PT-2021-19848 · Zope · Zope

Dataflake

·

Published

2021-05-21

·

Updated

2022-01-21

·

CVE-2021-32674

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zope versions prior to 5.2.1 and 4.6.1
Description Zope is an open-source web application server. The issue concerns TAL expression traversal vulnerabilities, where most Python modules are not available for use in TAL expressions added through the web, but some untrusted modules can be accessed indirectly. By default, only users with the Manager role can add or edit Zope Page Templates through the web. However, sites allowing untrusted users to add or edit these templates are at risk. The problem has been fixed in versions 5.2.1 and 4.6.1.
Recommendations For versions prior to 5.2.1, update to version 5.2.1 to resolve the issue. For versions prior to 4.6.1, update to version 4.6.1 to resolve the issue. As a temporary workaround, a site administrator can restrict adding or editing Zope Page Templates through the web using standard Zope user/role permission mechanisms. Untrusted users should not be assigned the Zope Manager role, and adding or editing Zope Page Templates through the web should be restricted to trusted users only.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32674
GHSA-5PR9-V234-JW36
GHSA-5VQ5-PG3R-9PH3
GHSA-962M-M8JW-8WRR
GHSA-RPCG-F9Q6-2MQ6
PYSEC-2021-104
PYSEC-2021-88

Affected Products

Zope