Description
Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x before 3.9.0c2, when certain ZEO database sharing and blob support are enabled, allows remote authenticated users to read or delete arbitrary files via unknown vectors.
References (4)
Core 4
Core References
Patch mailing-list
x_refsource_mlist
https://mail.zope.org/pipermail/zope-announce/2009-September/002221.html
Patch x_refsource_confirm
http://pypi.python.org/pypi/ZODB3/3.8.3
Patch, Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/2534
Patch x_refsource_confirm
http://pypi.python.org/pypi/ZODB3/3.9.0c2
Scores
EPSS
0.0097
EPSS Percentile
58.2%
Details
Status
published
Products (12)
pypi/ZODB3
3.8 - 3.8.3PyPI
zope/zodb
3.8
zope/zodb
3.8.0
zope/zodb
3.8.1
zope/zodb
3.8.2
zope/zodb
3.9.0
zope/zodb
3.9.0b1
zope/zodb
3.9.0b2
zope/zodb
3.9.0b3
zope/zodb
3.9.0b4
... and 2 more
Published
Sep 08, 2009
Tracked Since
Feb 18, 2026