QID 995309
Date Published: 2023-09-21
QID 995309: Python (Pip) Security Update for zope (GHSA-h2xh-jvpf-xq42)
Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-h2xh-jvpf-xq42 for updates and patch information.
Vendor References
- GHSA-h2xh-jvpf-xq42 -
github.com/advisories/GHSA-h2xh-jvpf-xq42
CVEs related to QID 995309
Software Advisories
| Advisory ID | Software | Component | Link |
|---|