CVE-2000-1212: Medium severity Zope Zope vulnerability
Published Dec 18, 2000
·Updated
Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.
Affected Software
12 affected components
pip/zope>=2.2.0<=2.2.4
Zope Zope=2.2.0
Zope Zope=2.2.0a1
Zope Zope=2.2.0b1
Zope Zope=2.2.0b2
Zope Zope=2.2.0b3
Zope Zope=2.2.0b4
Zope Zope=2.2.1
Zope Zope=2.2.1b1
Zope Zope=2.2.2
Zope Zope=2.2.3
Zope Zope=2.2.4
Remediation
Event History
Dec 18, 2000
CVE Published
05:00 AM
Apr 2, 2003
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Apr 30, 2022
Advisory Published
06:15 PM
Frequently Asked Questions
1
What is the severity of CVE-2000-1212?
CVE-2000-1212 is considered a medium severity vulnerability due to the potential for unauthorized data modification.
2
How do I fix CVE-2000-1212?
To fix CVE-2000-1212, upgrade to Zope version 2.2.5 or later, where the vulnerability has been addressed.
3
What types of objects are affected by CVE-2000-1212?
CVE-2000-1212 affects Image and File objects in Zope that do not properly protect data updating methods.
4
Who is at risk from CVE-2000-1212?
Users with DTML editing privileges are at risk from CVE-2000-1212 as they can modify raw data in vulnerable objects.
5
Which versions of Zope are impacted by CVE-2000-1212?
CVE-2000-1212 impacts Zope versions 2.2.0 through 2.2.4.