VDB
KO
HIGH

GHSA-8w48-m6hx-rjw2

Zope Command Execution Vulnerability

Details

Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the `p_` class in `OFS/misc_.py` and the use of Python modules.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / zope2
Introduced in: 2.12.0 Fixed in: 2.12.20
Fix pip install --upgrade 'zope2>=2.12.20'
PyPI / zope2
Introduced in: 2.13.0 Fixed in: 2.13.10
Fix pip install --upgrade 'zope2>=2.13.10'

References