First published: Fri Oct 13 2000(Updated: )
Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zope Zope | =1.10.3 | |
Zope Zope | =2.1.1 | |
Zope Zope | =2.2_beta1 | |
Zope Zope | =2.1.7 | |
pip/zope | <2.2.1 | 2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.