First published: Wed Oct 10 2001(Updated: )
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zope ZODB | =2.2.0 | |
Zope ZODB | =2.2.1 | |
Zope ZODB | =2.2.2 | |
Zope ZODB | =2.2.3 | |
Zope ZODB | =2.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1278 has a moderate severity rating due to its ability to allow partially trusted users to bypass security controls.
To fix CVE-2001-1278, upgrade Zope software to version 2.2.4 or later.
CVE-2001-1278 affects Zope versions 2.2.0 through 2.2.3.
Yes, CVE-2001-1278 can potentially allow unauthorized access to sensitive methods by exploiting the fmt attribute.
Currently, the recommended approach is to update to the patched version since there are no documented effective workarounds.