CVE-2024-51734

CVSS V2 None CVSS V3 None
Description
Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This problem has been fixed in version 7.2. Users are advised to upgrade. Users unable to upgrade may address the issue by adding `data__roles__ = ()` to `AccessControl.userfolder.UserFolder`.
Overview
  • CVE ID
  • CVE-2024-51734
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-11-04T22:25:22.076Z
  • Last Modified Date
  • 2024-11-04T22:25:22.076Z
History
Created Old Value New Value Data Type Notes
2024-11-05 13:13:31 Added to TrackCVE