ZDI-24-841: (0Day) Zope CMFCore Uncontrolled Resource Consumption Denial-of-Service Vulnerability
Published Jun 21, 2024
·Updated
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Zope Application Server. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.
Affected Software
1 affected component
Zope Application Server
Event History
Jun 21, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-841?
The severity of ZDI-24-841 is rated at 7.5 on the CVSS scale, indicating a high level of risk.
2
How do I fix ZDI-24-841?
To fix ZDI-24-841, update the Zope Application Server to the latest version provided by the vendor.
3
Who can exploit ZDI-24-841?
Network-adjacent attackers can exploit ZDI-24-841 without requiring authentication.
4
What type of vulnerability is ZDI-24-841?
ZDI-24-841 is a denial-of-service vulnerability affecting Zope Application Server.
5
What are the potential impacts of ZDI-24-841?
The potential impact of ZDI-24-841 includes causing a denial-of-service condition that disrupts the functionality of the affected server.