Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3250 | Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This problem has been fixed in version 7.2. Users are advised to upgrade. Users unable to upgrade may address the issue by adding `data__roles__ = ()` to `AccessControl.userfolder.UserFolder`. |
Github GHSA |
GHSA-g5vw-3h65-2q3v | Access control vulnerable to user data deletion by anonynmous users |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 22 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 05 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zope
Zope accesscontrol |
|
| CPEs | cpe:2.3:a:zope:accesscontrol:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zope
Zope accesscontrol |
|
| Metrics |
cvssV3_1
|
Mon, 04 Nov 2024 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This problem has been fixed in version 7.2. Users are advised to upgrade. Users unable to upgrade may address the issue by adding `data__roles__ = ()` to `AccessControl.userfolder.UserFolder`. | |
| Title | User data deletion by anoynmous users in Zope | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-22T20:12:19.451Z
Reserved: 2024-10-31T14:12:45.788Z
Link: CVE-2024-51734
Updated: 2024-11-05T20:05:07.911Z
Status : Awaiting Analysis
Published: 2024-11-04T23:15:05.213
Modified: 2025-01-22T20:15:30.610
Link: CVE-2024-51734
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA