QID 995312
Date Published: 2023-09-21
QID 995312: Python (Pip) Security Update for zope (GHSA-9cmq-pj6p-hgwf)
Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9cmq-pj6p-hgwf for updates and patch information.
Vendor References
- GHSA-9cmq-pj6p-hgwf -
github.com/advisories/GHSA-9cmq-pj6p-hgwf
CVEs related to QID 995312
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9cmq-pj6p-hgwf | zope |
|