First published: Fri Jul 27 2001(Updated: )
Digital Creations Zope 2.3.1 b1 and earlier allows a local attacker (Zope user) with through-the-web scripting capabilities to alter ZClasses class attributes.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zope ZODB | <=2.3.1_b1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0568 is considered a moderate severity vulnerability as it allows local attackers to modify class attributes.
To fix CVE-2001-0568, upgrade to Zope version 2.3.1b2 or later.
CVE-2001-0568 affects users of Digital Creations Zope 2.3.1 b1 and earlier versions.
CVE-2001-0568 enables local attackers with scripting capabilities to alter ZClasses class attributes.
No, user authentication alone is not sufficient to mitigate CVE-2001-0568 as it allows any local Zope user with scripting access to exploit the vulnerability.