Metrics
Affected Vendors & Products
Wed, 22 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 05 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zope
Zope accesscontrol |
|
| CPEs | cpe:2.3:a:zope:accesscontrol:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zope
Zope accesscontrol |
|
| Metrics |
cvssV3_1
|
Mon, 04 Nov 2024 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This problem has been fixed in version 7.2. Users are advised to upgrade. Users unable to upgrade may address the issue by adding `data__roles__ = ()` to `AccessControl.userfolder.UserFolder`. | |
| Title | User data deletion by anoynmous users in Zope | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-04T22:25:22.076Z
Updated: 2025-01-22T20:12:19.451Z
Reserved: 2024-10-31T14:12:45.788Z
Link: CVE-2024-51734
Updated: 2024-11-05T20:05:07.911Z
Status : Awaiting Analysis
Published: 2024-11-04T23:15:05.213
Modified: 2025-01-22T20:15:30.610
Link: CVE-2024-51734
No data.