zope
PyPI18 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting zopepage 1 of 1
- CVE-2000-0062HIGHCVSS v2 10.0EG 10.02000-01-04
The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.
- CVE-2000-0483HIGHCVSS v2 7.5EG 7.52000-06-15
The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.
- CVE-2000-0725HIGHCVSS v2 7.2EG 7.2✓ Fixed in 2.2.12000-10-20
Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.
- CVE-2000-1211HIGHCVSS v2 7.5EG 7.52000-12-16
Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.
- CVE-2000-1212MEDIUMCVSS v2 5.0EG 5.02000-12-18
Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.
- CVE-2002-0170HIGHCVSS v2 7.5EG 7.5✓ Fixed in 2.5.12002-04-22
Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violation of the intended configuration.
- CVE-2002-0687MEDIUMCVSS v2 5.0EG 5.0✓ Fixed in 2.5.1b22002-07-23
The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.
- CVE-2002-0688HIGHCVSS v2 7.5EG 7.5✓ Fixed in 2.6.02002-07-23
ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.
- CVE-2010-3198MEDIUMCVSS v2 4.3EG 4.32010-09-08
ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker threads) via vectors that trigger uncaught exceptions.
- CVE-2011-4924MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.7.32019-11-25
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script o…
- CVE-2021-32633MEDIUMCVSS 6.8EG 6.8✓ Fixed in 5.22021-05-21
vulnerable: 4.0 ... 5.1.2 (33 versions)
Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules indirectly through Python modules that are available for direct use. By default, only users with the Manager role can …
- CVE-2021-32674HIGHCVSS 8.8EG 8.8✓ Fixed in 5.2.12021-06-08
vulnerable: 4.0 ... 4.0a1 (43 versions)
Zope is an open-source web application server. This advisory extends the previous advisory at https://github.com/zopefoundation/Zope/security/advisories/GHSA-5pr9-v234-jw36 with additional cases of TAL expression traversal vulnerabilities.…
- CVE-2021-32807MEDIUMCVSS 4.4EG 4.4✓ Fixed in 5.22021-07-30
vulnerable: 4.0 ... 3.0.7 (30 versions)
The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. Restricted code is any code that resides in Zope's object database, such as the contents of `Script (Python)` objects. T…
- CVE-2021-32811HIGHCVSS 7.5EG 7.5✓ Fixed in 5.32021-08-02
vulnerable: 4.0 ... 4.0a1 (46 versions)
Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code execution security issue. In order to be affected, one must use Python 3 for one's Zope deployment, run Zope 4 below version 4.…
- CVE-2023-41050HIGHCVSS 7.7EG 7.7✓ Fixed in 5.8.42023-09-06
vulnerable: 4.0 ... 5.8.3 (63 versions)
AccessControl provides a general security framework for use in Zope. Python's "format" functionality allows someone controlling the format string to "read" objects accessible (recursively) via attribute access and subscription from accessi…
- CVE-2023-42458MEDIUMCVSS 5.4EG 5.4✓ Fixed in 5.8.52023-09-21
vulnerable: 4.0 ... 5.8.4 (49 versions)
Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scripting vulnerability for SVG images. Note that an image tag with an SVG image as source is never vulnerable, even when the S…
- CVE-2023-44389MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.8.112023-10-04
vulnerable: 4.0 ... 5.8.5 (57 versions)
Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store script code that is executed while viewing the affected object in the Zope Management Interface (ZMI). All versions of …
- CVE-2024-51734HIGHCVSS 8.7EG 8.7✓ Fixed in 5.11.12024-11-04
vulnerable: 4.0 ... 5.9 (74 versions)
Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This pr…
Check whether zope is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for zope CVEs against the assets you own.
Start Free Scan →