Red Hat Essential and Critical Security Patch Updates

Find the information you need for your favorite open source distribution .

RedHat: 'Zope' unauthorized access vulnerability

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The issue involves the fmt attribute of dtml-var tags.Without this correction, Zope does not check security access to methodsinvoked through fmt. This issue could allow partially trusted users withenough knowledge of Zope to call, in a limited way, methods they would nototherwise be allowed to access.