QID 996725

Date Published: 2024-01-17

QID 996725: Python (Pip) Security Update for zope2 (GHSA-8w48-m6hx-rjw2)

Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Refer to Github security advisory GHSA-8w48-m6hx-rjw2 for updates and patch information.
    Vendor References

    CVEs related to QID 996725

    Software Advisories
    Advisory ID Software Component Link
    GHSA-8w48-m6hx-rjw2 zope2 URL Logo github.com/advisories/GHSA-8w48-m6hx-rjw2