zope
PyPI18 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting zopepage 1 of 1
- CVE-2000-0062NONECVSS 0.02000-01-04
The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.
- CVE-2000-0483NONECVSS 0.02000-06-15
The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.
- CVE-2000-0725NONECVSS 0.0✓ Fixed in 2.2.12000-10-20
Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.
- CVE-2000-1211NONECVSS 0.02000-12-16
Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.
- CVE-2000-1212NONECVSS 0.02000-12-18
Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.
- CVE-2002-0170NONECVSS 0.0✓ Fixed in 2.5.12002-04-22
Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violation of the intended configuration.
- CVE-2002-0687NONECVSS 0.0✓ Fixed in 2.5.1b22002-07-23
The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.
- CVE-2002-0688NONECVSS 0.0✓ Fixed in 2.6.02002-07-23
ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.
- CVE-2010-3198NONECVSS 0.02010-09-08
ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker threads) via vectors that trigger uncaught exceptions.
- CVE-2011-4924MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.7.32019-11-25
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script o…
- CVE-2021-32633MEDIUMCVSS 6.8EG 6.8✓ Fixed in 5.22021-05-21
vulnerable: 4.0 ... 5.1.2 (33 versions)
Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules indirectly through Python modules that are available for direct use. By default, only users with the Manager role can …
- CVE-2021-32674HIGHCVSS 8.8EG 8.8✓ Fixed in 5.22021-06-08
vulnerable: 4.0 ... 5.1.2 (33 versions)
Zope is an open-source web application server. This advisory extends the previous advisory at https://github.com/zopefoundation/Zope/security/advisories/GHSA-5pr9-v234-jw36 with additional cases of TAL expression traversal vulnerabilities.…
- CVE-2021-32807MEDIUMCVSS 4.4EG 4.4✓ Fixed in 4.32021-07-30
vulnerable: 4.0 ... 5.1.2 (11 versions)
The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. Restricted code is any code that resides in Zope's object database, such as the contents of `Script (Python)` objects. T…
- CVE-2021-32811HIGHCVSS 7.5EG 7.5✓ Fixed in 4.32021-08-02
vulnerable: 4.0 ... 5.1.2 (11 versions)
Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code execution security issue. In order to be affected, one must use Python 3 for one's Zope deployment, run Zope 4 below version 4.…
- CVE-2023-41050MEDIUMCVSS 6.8EG 6.8✓ Fixed in 5.8.42023-09-06
vulnerable: 5.0 ... 5.8.3 (20 versions)
AccessControl provides a general security framework for use in Zope. Python's "format" functionality allows someone controlling the format string to "read" objects accessible (recursively) via attribute access and subscription from accessi…
- CVE-2023-42458LOWCVSS 3.7EG 3.7✓ Fixed in 5.8.52023-09-21
vulnerable: 5.8, 5.8.1, 5.8.2, 5.8.3, 5.8.4
Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scripting vulnerability for SVG images. Note that an image tag with an SVG image as source is never vulnerable, even when the S…
- CVE-2023-44389LOWCVSS 3.1EG 3.1✓ Fixed in 4.8.112023-10-04
vulnerable: 4.0 ... 5.8.5 (57 versions)
Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store script code that is executed while viewing the affected object in the Zope Management Interface (ZMI). All versions of …
- CVE-2024-51734HIGHCVSS 8.7EG 0.0✓ Fixed in 5.11.12024-11-04
vulnerable: 4.0 ... 5.9 (74 versions)
Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This pr…
Check whether zope is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for zope CVEs against the assets you own.
Start Free Scan →