Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This problem has been fixed in version 7.2. Users are advised to upgrade. Users unable to upgrade may address the issue by adding `data__roles__ = ()` to `AccessControl.userfolder.UserFolder`.
Metrics
Affected Vendors & Products
References
History
Tue, 05 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Zope
Zope accesscontrol |
|
CPEs | cpe:2.3:a:zope:accesscontrol:*:*:*:*:*:*:*:* | |
Vendors & Products |
Zope
Zope accesscontrol |
|
Metrics |
cvssV3_1
|
Mon, 04 Nov 2024 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This problem has been fixed in version 7.2. Users are advised to upgrade. Users unable to upgrade may address the issue by adding `data__roles__ = ()` to `AccessControl.userfolder.UserFolder`. | |
Title | User data deletion by anoynmous users in Zope | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-04T22:25:22.076Z
Updated: 2024-11-21T16:24:36.862Z
Reserved: 2024-10-31T14:12:45.788Z
Link: CVE-2024-51734
Vulnrichment
Updated: 2024-11-05T20:05:07.911Z
NVD
Status : Awaiting Analysis
Published: 2024-11-04T23:15:05.213
Modified: 2024-11-05T20:35:26.167
Link: CVE-2024-51734
Redhat
No data.