CVE-2000-0725
Summary
| CVE | CVE-2000-0725 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2000-10-20 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request. |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zope Unauthorized Role Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| Zope security alert and hotfix product | af854a3a-2127-422b-91ae-364da2661108 | www.zope.org | |
| Debian -- Security Information -- zope | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Vendor Advisory |
| archives.neohapsis.com/archives/bugtraq/2000-08/0259.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Patch |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| archives.neohapsis.com/archives/bugtraq/2000-08/0198.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995312 Python (Pip) Security Update for zope (GHSA-9cmq-pj6p-hgwf)