CVE-2002-0688: High severity Zope Zope vulnerability
Published Jul 23, 2002
·Updated
ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.
Affected Software
3 affected componentsFixes available
pip/zope>=2.4.0<=2.5.1
2.6.0
Zope Zope=2.4.0
Zope Zope=2.5.1
Remediation
Event History
Jul 23, 2002
CVE Published
via NVD·04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Apr 30, 2022
Advisory Published
via GitHub·06:19 PM
Frequently Asked Questions
1
What is the severity of CVE-2002-0688?
CVE-2002-0688 is considered a critical vulnerability due to the potential for unauthorized access by anonymous users.
2
How do I fix CVE-2002-0688?
To fix CVE-2002-0688, upgrade to Zope version 2.6.0 or later.
3
Which versions of Zope are affected by CVE-2002-0688?
CVE-2002-0688 affects Zope versions 2.4.0 through 2.5.1.
4
What type of access does CVE-2002-0688 allow malicious users?
CVE-2002-0688 allows malicious users to bypass access restrictions and invoke arbitrary methods on catalog indexes.
5
Is CVE-2002-0688 a known vulnerability in Zope?
Yes, CVE-2002-0688 is a well-documented vulnerability that has been reported in Zope's security advisory.