GHSA-m52m-2qpx-9j4j
Dashboard / Vulnerabilities / GHSA-m52m-2qpx-9j4j
GHSA-m52m-2qpx-9j4j
Summary: Zope Object Database (ZODB) Arbitrary files reading and deletion
Details: Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x before 3.9.0c2, when certain ZEO database sharing and blob support are enabled, allows remote authenticated users to read or delete arbitrary files via unknown vectors.
References: https://nvd.nist.gov/vuln/detail/CVE-2009-2701, https://github.com/pypa/advisory-database/tree/main/vulns/zodb3/PYSEC-2009-10.yaml, https://github.com/zopefoundation/ZODB3, https://mail.zope.org/pipermail/zope-announce/2009-September/002221.html, http://pypi.python.org/pypi/ZODB3/3.8.3, http://pypi.python.org/pypi/ZODB3/3.9.0c2
Affected packages
Package
Name: zodb3
Purl: pkg:pypi/zodb3
Affected ranges
Type: ECOSYSTEM
Events:
