ZDI-CAN-21491: ZDI-24-841: (0Day) Zope CMFCore Uncontrolled Resource Consumption Denial-of-Service Vulnerability
Published Jun 21, 2024
·Updated
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Zope Application Server. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.
Affected Software
1 affected component
Zope Zope Application Server
Event History
Jun 21, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-21491?
The severity of ZDI-CAN-21491 is rated at 7.5 on the CVSS scale, indicating a high risk.
2
How do I fix ZDI-CAN-21491?
To fix ZDI-CAN-21491, ensure that you update your Zope Application Server to the latest version that addresses this vulnerability.
3
Who can exploit ZDI-CAN-21491?
ZDI-CAN-21491 can be exploited by network-adjacent attackers, as no authentication is required.
4
What type of attack does ZDI-CAN-21491 enable?
ZDI-CAN-21491 enables a denial-of-service condition on affected installations of the Zope Application Server.
5
Which software is affected by ZDI-CAN-21491?
The affected software for ZDI-CAN-21491 is the Zope Application Server.