VDB
KO
MEDIUM

GHSA-vwrc-g9q6-f675

Zope Server vulnerable to DoS via header injection

Details

Zope is a Web application server for Linux. Zope versions 2.0 through 2.5.1 b1 are vulnerable to a denial of service attack, caused by a vulnerability that occurs when using the "through the Web code" capability. A remote attacker could inject malicious headers into a response to cause the vulnerable system to crash.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / zope
Introduced in: 2.0.0 Fixed in: 2.4.4b2
Fix pip install --upgrade 'zope>=2.4.4b2'
PyPI / zope
Introduced in: 2.5.0 Fixed in: 2.5.1b2
Fix pip install --upgrade 'zope>=2.5.1b2'

References