Zope does not properly perform security registration for legacy names
High severity
GitHub Reviewed
Published
Apr 30, 2022
to the GitHub Advisory Database
•
Updated Sep 18, 2023
Description
Published by the National Vulnerability Database
Dec 16, 2000
Published to the GitHub Advisory Database
Apr 30, 2022
Last updated
Sep 18, 2023
Reviewed
Sep 18, 2023
Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.
References