QID 980966

QID 980966: Python (pip) Security Update for Zope2 (GHSA-p6h9-hpcg-c6gm)

Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) PloneHotfix20110720 for Plone 3.x allows attackers to gain privileges via unspecified vectors, related to a "highly serious vulnerability." NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-0720.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 4.2 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-p6h9-hpcg-c6gm for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980966

    Software Advisories
    Advisory ID Software Component Link
    GHSA-p6h9-hpcg-c6gm Plone URL Logo github.com/advisories/GHSA-p6h9-hpcg-c6gm
    GHSA-p6h9-hpcg-c6gm Zope2 URL Logo github.com/advisories/GHSA-p6h9-hpcg-c6gm