Race condition in Zope - CVE-2012-5507
Published: September 30, 2014 / Updated: June 8, 2025
Zope
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.