Skip to content

User data deletion by anoynmous users

High
tseaver published GHSA-g5vw-3h65-2q3v Nov 4, 2024

Package

AccessControl

Affected versions

< 7.2

Patched versions

7.2
Zope
< 5.11.1
5.11.1

Description

Impact

Anonymous users can delete the user data maintained by an AccessControl.userfolder.UserFolder which may prevent any privileged access.

Patches

The problem is fixed in version 7.2.

Workarounds

The problem can be fixed by adding data__roles__ = () to AccessControl.userfolder.UserFolder.

References

#159

Severity

High

CVE ID

CVE-2024-51734

Weaknesses

No CWEs

Credits