GHSA-jcjp-qqpq-pc54
Dashboard / Vulnerabilities / GHSA-jcjp-qqpq-pc54
Summary: Zope allows local users to read arbitrary files
Details: Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.
References: https://nvd.nist.gov/vuln/detail/CVE-2006-3458, https://exchange.xforce.ibmcloud.com/vulnerabilities/27636, https://github.com/pypa/advisory-database/tree/main/vulns/zope2/PYSEC-2006-7.yaml, https://github.com/zopefoundation/Zope, https://usn.ubuntu.com/317-1, http://mail.zope.org/pipermail/zope-announce/2006-July/001984.html, http://www.debian.org/security/2006/dsa-1113, http://www.novell.com/linux/security/advisories/2006_19_sr.html
Affected packages
Package
Name: zope2
Purl: pkg:pypi/zope2
Affected ranges
Type: ECOSYSTEM
Events:
