Логотип exploitDog
bind:CVE-2024-51734
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-51734

Количество 2

Количество 2

nvd логотип

CVE-2024-51734

больше 1 года назад

Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This problem has been fixed in version 7.2. Users are advised to upgrade. Users unable to upgrade may address the issue by adding `data__roles__ = ()` to `AccessControl.userfolder.UserFolder`.

EPSS: Низкий
github логотип

GHSA-g5vw-3h65-2q3v

больше 1 года назад

Access control vulnerable to user data deletion by anonynmous users

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-51734

Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This problem has been fixed in version 7.2. Users are advised to upgrade. Users unable to upgrade may address the issue by adding `data__roles__ = ()` to `AccessControl.userfolder.UserFolder`.

0%
Низкий
больше 1 года назад
github логотип
GHSA-g5vw-3h65-2q3v

Access control vulnerable to user data deletion by anonynmous users

CVSS3: 9.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу