CVE-2001-1278: High severity Zope Zope vulnerability
Published Oct 10, 2001
·Updated
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
Affected Software
5 affected components
Zope Zope=2.2.0
Zope Zope=2.2.1
Zope Zope=2.2.2
Zope Zope=2.2.3
Zope Zope=2.2.4
Remediation
Patch Available
Event History
Oct 10, 2001
CVE Published
04:00 AM
May 3, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1278?
CVE-2001-1278 has a moderate severity rating due to its ability to allow partially trusted users to bypass security controls.
2
How do I fix CVE-2001-1278?
To fix CVE-2001-1278, upgrade Zope software to version 2.2.4 or later.
3
What versions of Zope are affected by CVE-2001-1278?
CVE-2001-1278 affects Zope versions 2.2.0 through 2.2.3.
4
Can CVE-2001-1278 allow unauthorized access to sensitive methods?
Yes, CVE-2001-1278 can potentially allow unauthorized access to sensitive methods by exploiting the fmt attribute.
5
Is there a workaround for CVE-2001-1278?
Currently, the recommended approach is to update to the patched version since there are no documented effective workarounds.