You are not logged in Log in Join
You are here: Home » Download Zope Products » Zope » Hotfix_2000-12-15a » Zope hotfix: local roles computation » View NewsItem

Log in
Name

Password

 

Zope hotfix: local roles computation

This hotfix addresses an important security issue that affects Zope versions up to and including Zope 2.2.4.

The issue involves the computation of local roles. In some situations the computation was not climbing the correct hierarchy of folders, sometimes granting local roles inappropriately. This could allow users with privileges in one folder to gain the same privileges in another folder.

We highly recommend that any Zope site running versions of Zope up to and including 2.2.4 have this hotfix product installed to mitigate the issue.

README

http://www.zope.org/Products/Zope/Hotfix_2000-12-15a/Hotfix_2000-12-15a.tgz

The hotfix will work for all versions of Zope 2.1.x and higher. A future version of Zope will contain the fix for this issue, and you will be able to uninstall the hot fix after upgrading.