Lucene search

K
githubGitHub Advisory DatabaseGHSA-8W48-M6HX-RJW2
HistoryMay 17, 2022 - 5:37 a.m.

Zope Command Execution Vulnerability

2022-05-1705:37:39
GitHub Advisory Database
github.com
8
zope
plone
remote attackers
arbitrary commands
python modules
vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.1

Confidence

Low

EPSS

0.967

Percentile

99.7%

Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.

Affected configurations

Vulners
Node
zope2Range2.13.0–2.13.10
OR
zope2Range2.12.0–2.12.20
VendorProductVersionCPE
*zope2*cpe:2.3:a:*:zope2:*:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.1

Confidence

Low

EPSS

0.967

Percentile

99.7%