CVE-2001-1227: High severity Zope Zope vulnerability
Published Oct 10, 2001
·Updated
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
Affected Software
6 affected components
Zope Zope=2.2.0
Zope Zope=2.2.1
Zope Zope=2.2.2
Zope Zope=2.2.3
Zope Zope=2.2.4
Zope Zope=2.2.5
Remediation
Patch Available
Event History
Oct 10, 2001
CVE Published
04:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1227?
CVE-2001-1227 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2001-1227?
To fix CVE-2001-1227, upgrade Zope to version 2.2.4 or later.
3
Which versions of Zope are affected by CVE-2001-1227?
Versions 2.2.0 to 2.2.5 of Zope are affected by CVE-2001-1227.
4
What types of users are impacted by CVE-2001-1227?
Partially trusted users can bypass security controls due to CVE-2001-1227.
5
What methods can be accessed through CVE-2001-1227?
Certain methods can be accessed via the fmt attribute of dtml-var tags due to the vulnerability.