CVE-2001-0568: Low severity Zope Zope vulnerability
Published Jul 27, 2001
·Updated
Digital Creations Zope 2.3.1 b1 and earlier allows a local attacker (Zope user) with through-the-web scripting capabilities to alter ZClasses class attributes.
Affected Software
1 affected component
Zope Zope<=2.3.1_b1
Remediation
Patch Available
Patch Available
Event History
Jul 27, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0568?
CVE-2001-0568 is considered a moderate severity vulnerability as it allows local attackers to modify class attributes.
2
How do I fix CVE-2001-0568?
To fix CVE-2001-0568, upgrade to Zope version 2.3.1b2 or later.
3
Who is affected by CVE-2001-0568?
CVE-2001-0568 affects users of Digital Creations Zope 2.3.1 b1 and earlier versions.
4
What type of attack does CVE-2001-0568 enable?
CVE-2001-0568 enables local attackers with scripting capabilities to alter ZClasses class attributes.
5
Is user authentication sufficient to mitigate CVE-2001-0568?
No, user authentication alone is not sufficient to mitigate CVE-2001-0568 as it allows any local Zope user with scripting access to exploit the vulnerability.