Impact
Zope AccessControl, a security framework used by Zope applications, contains a flaw where Python's string formatting functions (str.format and str.format_map) can be abused when invoked on subclasses of str. The functions recursively traverse object attributes and subscriptions with unrestricted getattr and getitem operations, bypassing the framework's access policy. This permits a carefully crafted format string to reveal internal objects that are otherwise protected, leading to information disclosure. The weakness is classified as CWE-693, a failure to safeguard data that compromises confidentiality.
Affected Systems
The vulnerability exists in Zope Foundation's AccessControl component in all releases prior to 7.4. The fix was released in version 7.4, available as a patch on the project's GitHub releases page. Any Zope deployment that has not upgraded past 7.3 is potentially exposed, especially those that allow untrusted users to create or execute code that reaches these formatting functions.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, but the EPSS score of less than 1% suggests a very low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. Attackers would need to supply untrusted code or a malicious string subclass to trigger the vulnerable formatting path, which is typically an application-level threat rather than a network-level vector.
OpenCVE Enrichment
Github GHSA