You are not logged in Log in Join
You are here: Home » Download Zope Products » Zope » Hotfix_2001-09-28 » Zope Hotfix: DTML format method checking » View NewsItem

Log in
Name

Password

 

Zope Hotfix: DTML format method checking

This hotfix addresses an important security issue that affects Zope versions 2.2.0 through 2.4.1.

The issue involves the "fmt" attribute of dtml-var tags. Without this correction, Zope does not check security access to methods invoked through "fmt". This issue could allow partially trusted users with enough knowledge of Zope to call, in a limited way, methods they would not otherwise be allowed to access.

We highly recommend that any Zope site running Zope 2.2.0 through Zope 2.4.1 have this hotfix product installed to mitigate the issue. Zope 2.4.2 will contain a fix for the issue, at which time the hotfix can be removed.

README

http://www.zope.org/Products/Zope/Hotfix_2001-09-28