SB2025060834 - Permissions, Privileges, and Access Controls in Zope



SB2025060834 - Permissions, Privileges, and Access Controls in Zope

Published: June 8, 2025 Updated: June 17, 2025

Security Bulletin ID SB2025060834
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2012-5489)

The vulnerability allows a remote user to read and manipulate data.

The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.


Remediation

Install update from vendor's website.