You are not logged in Log in Join
You are here: Home » Download Zope Products » Zope » Hotfix_2002-06-14 » Hotfix 2002-06-14 Alert

Log in



Hotfix 2002-06-14 Alert

This hotfix addresses an important security issue that affects users of Zope versions 2.4.0 through 2.5.1 (or other Zope versions with ZCatalog's plug-in index support installed)

The issue involves the security of the indexes of ZCatalog objects. A flaw in the security settings of ZCatalog allows anonymous users to call arbitrary methods of catalog indexes. The vulnerability also allows untrusted code to do the same.

We highly recommend that any Zope site running Zope 2.4.0 through Zope 2.5.1 have this hotfix product installed to mitigate the issue. Zope 2.6 will contain a fix for the issue, at which time the hotfix can be removed.

You may obtain this hotfix at: