Input validation error in Zope - CVE-2001-0128

 

Input validation error in Zope - CVE-2001-0128

Published: October 10, 2017 / Updated: June 17, 2025


Vulnerability identifier: #VU111198
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2001-0128
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Zope
Affected software:
Zope

Detailed vulnerability description

The vulnerability allows a local user to execute arbitrary code.

Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.


How to mitigate CVE-2001-0128

Install update from vendor's website.

Sources