Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violation of the intended configuration.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=101503023511996&w=2 | mailing list |
http://www.zope.org/Products/Zope/hotfixes/ | patch vendor advisory |
http://www.securityfocus.com/bid/4229 | vdb entry |
http://www.redhat.com/support/errata/RHSA-2002-060.html | vendor advisory |
http://www.iss.net/security_center/static/8334.php | vdb entry |
http://www.osvdb.org/5350 | vdb entry |