CVE Vulnerabilities

CVE-2001-1227

Published: Oct 10, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.

Affected Software

NameVendorStart VersionEnd Version
ZopeZope2.2.0 (including)2.2.0 (including)
ZopeZope2.2.1 (including)2.2.1 (including)
ZopeZope2.2.2 (including)2.2.2 (including)
ZopeZope2.2.3 (including)2.2.3 (including)
ZopeZope2.2.4 (including)2.2.4 (including)
ZopeZope2.2.5 (including)2.2.5 (including)
Red Hat Linux 5.2RedHat*
Red Hat Linux 6.2RedHat*
Red Hat Linux 7.0RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Powertools 6.2RedHat*
Red Hat Powertools 7.0RedHat*
Red Hat Powertools 7.1RedHat*

References