Back

HIGH

security flaw

Published Oct 13, 2000

Description

Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.

Affected products

Remediation

Red Hat statement

This issue was fixed in the following products: - Red Hat Powertools 6.1 - RHSA-2000:052 (2000-08-11) - Red Hat Powertools 6.2 - RHSA-2000:052 (2000-08-11)

Metrics

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 13, 2000
Updated Aug 8, 2024
Reserved Sep 19, 2000
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Aug 10, 2000
GHSA-9CMQ-PJ6P-HGWF