Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3250 | Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This problem has been fixed in version 7.2. Users are advised to upgrade. Users unable to upgrade may address the issue by adding `data__roles__ = ()` to `AccessControl.userfolder.UserFolder`. |
Github GHSA |
GHSA-g5vw-3h65-2q3v | Access control vulnerable to user data deletion by anonynmous users |
Wed, 22 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 05 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zope
Zope accesscontrol |
|
| CPEs | cpe:2.3:a:zope:accesscontrol:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zope
Zope accesscontrol |
|
| Metrics |
cvssV3_1
|
Mon, 04 Nov 2024 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This problem has been fixed in version 7.2. Users are advised to upgrade. Users unable to upgrade may address the issue by adding `data__roles__ = ()` to `AccessControl.userfolder.UserFolder`. | |
| Title | User data deletion by anoynmous users in Zope | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-22T20:12:19.451Z
Reserved: 2024-10-31T14:12:45.788Z
Link: CVE-2024-51734
Updated: 2024-11-05T20:05:07.911Z
Status : Deferred
Published: 2024-11-04T23:15:05.213
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-51734
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA