CVE-2009-0669: High severity Zope ZODB vulnerability
Published Aug 7, 2009
·Updated
Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass authentication via vectors involving the ZEO network protocol.
Affected Software
4 affected componentsFixes available
pip/ZODB3<3.8.2
3.8.2
Zope ZODB<=3.8.1
Zope ZODB=3.8.0
Zope ZODB=3.8
Remediation
Event History
Aug 7, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
May 2, 2022
Advisory Published
via GitHub·03:17 AM
Frequently Asked Questions
1
What is the severity of CVE-2009-0669?
CVE-2009-0669 is classified as a medium severity vulnerability due to its potential for authentication bypass.
2
How do I fix CVE-2009-0669?
To fix CVE-2009-0669, update your Zope Object Database (ZODB) to version 3.8.2 or later.
3
Which versions of ZODB are affected by CVE-2009-0669?
CVE-2009-0669 affects ZODB versions prior to 3.8.2, specifically 3.8.0 and 3.8.1.
4
What type of attack does CVE-2009-0669 enable?
CVE-2009-0669 enables remote attackers to bypass authentication through vulnerabilities in the ZEO network protocol.
5
Is there a workaround for CVE-2009-0669 until I can patch?
There are no defined workarounds for CVE-2009-0669, so immediate updating to a secure version is recommended.