Description
Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.
References (5)
Core 5
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www.zope.org/Products/Zope/Hotfix_2000-12-08/security_alert
Patch, Vendor Advisory vendor-advisory
x_refsource_mandrake
http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-083.php3
Third Party Advisory vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/5824.php
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2000-125.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/6282
Scores
EPSS
0.0143
EPSS Percentile
70.2%
Details
Status
published
Products (12)
pypi/zope
2.2.0PyPI
zope/zope
2.2.0
zope/zope
2.2.0a1
zope/zope
2.2.0b1
zope/zope
2.2.0b2
zope/zope
2.2.0b3
zope/zope
2.2.0b4
zope/zope
2.2.1
zope/zope
2.2.1b1
zope/zope
2.2.2
... and 2 more
Published
Dec 16, 2000
Tracked Since
Feb 18, 2026