Race condition in Zope - CVE-2012-5507

 

Race condition in Zope - CVE-2012-5507

Published: September 30, 2014 / Updated: June 8, 2025


Vulnerability identifier: #VU41268
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2012-5507
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Zope
Affected software:
Zope

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.


How to mitigate CVE-2012-5507

Install update from vendor's website.

Sources