Zope 4.6.1 and 5.2.1 released with an important security fix
Jens Vagelpohl <[email protected]> Tue, 8 Jun 2021 10:46:35 +0200
| Newsgroups | gmane.comp.web.zope.announce,gmane.comp.web.zope.general |
|---|---|
| Message-ID | <[email protected]> |
--===============6055500738027040851== Content-Type: multipart/signed; boundary="Apple-Mail=_920C9A39-6810-45AF-B960-CB0C1734A8A0"; protocol="application/pgp-signature"; micalg=pgp-sha512 --Apple-Mail=_920C9A39-6810-45AF-B960-CB0C1734A8A0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=us-ascii On behalf of Zope developer community I am pleased to announce the = releases of Zope 4.6.1 and 5.2.1. This bugfix release solves a few minor issues and also contains an = important security fix, see below. For the full list of changes see the = change logs at https://zope.readthedocs.io/en/4.x/changes.html#id1 and = https://zope.readthedocs.io/en/latest/changes.html#id1 Installation instructions can be found at = https://zope.readthedocs.io/en/4.x/INSTALL.html and = https://zope.readthedocs.io/en/latest/INSTALL.html. NOTE: These releases contain an expanded security fix that prevents = remote code execution through TAL expressions. The first iteration of = the security fix in Zope 4.6 and 5.2 did not catch all cases of = unauthorized TAL path expression traversal. Just like the first fix, you = will only ever be at risk if you allow untrusted users to add or edit = Zope Page Template objects, which is a very unusual non-standard site = configuration. For more details, see the security advisory at = https://github.com/zopefoundation/Zope/security/advisories/GHSA-rpcg-f9q6-= 2mq6. A CVE has been requested through GitHub. NOTE FOR PLONE USERS: Make sure to install the latest version of = PloneHotfix20210518 first, which should appear shortly after this Zope = release. See https://plone.org/security/hotfix/20210518. Don't install = Zope 4.6.1 or 5.2.1 into an existing Plone setup without testing. The = security changes in Zope break some Plone add-ons that relied on the old = insecure traversal behavior. PloneHotfix20210518 ensures support for = those Plone add-ons. Jens Vagelpohl --Apple-Mail=_920C9A39-6810-45AF-B960-CB0C1734A8A0 Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=signature.asc Content-Type: application/pgp-signature; name=signature.asc Content-Description: Message signed with OpenPGP -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEci4R3bPsmS6uSKPIwbdNWZil9lcFAmC/LmsACgkQwbdNWZil 9lfTOg/+IwxZ7HbSRPWINM06dzonHSx3wezJaF1h456tLJpvD5krOt3bOnwuICxz Cix85SzuEb3mte/bEs7B6T4VXkCgG+gtmyPRPtIM/smRWkVqScAZSL3dtS5e+4Vy NPl47HiunJZP/k2Z5OBPsve593DPqNaBK6ubgoiO7o+g1UEKXANiz0UtIh7n15cJ yqTxB/SY4Py/3J4gLuem6uNggZMs0Qvo3iXdmgLiFfOGRvRbFj9bVwEwL+hAgtew 30ddmBscpez/tqYyNCfJKUIIEVRJwyndAlrtQcLfONE2nKKYpdyal5DiZi4GYiJl PNR6u+0dps5qKoTAxbTnFW1cGg2+EMhDAxjTxD9fmXeaa/Os4DgCQ/DBGPhUCKs3 NAOHJdBTGuVEWv9ggf4x6f00/A3Wm2XHdU41HmJG4yQCghSrrbDgvBmBji1guREn G7V6yxJlv4eO3zd55K7SpKuHvUmzqVHgwxiR+5u5/0um3RYcdIGdvUojh6S7hlz1 W+dcYnHWtbooBYZNnH9mJousIoUkSdjtKVRCIq+OEJLhj7UKFDluiaK0xadbFa+p HE2Mm1kp0AQrAN0JgZhBNbZ4vKFWC73v1lPbi36zxpOJIuOBxwzt2GM9Vjy+JDTP /t9ZTmjGAukc9KHa/q5XJ6p/5l7xTsTeyCknFPTm8b83kEuu4ic= =Z6oj -----END PGP SIGNATURE----- --Apple-Mail=_920C9A39-6810-45AF-B960-CB0C1734A8A0-- --===============6055500738027040851== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Zope-Announce maillist - [email protected] https://mail.zope.org/mailman/listinfo/zope-announce Zope-Announce for Announcements only - no discussions (Related lists - Users: https://mail.zope.org/mailman/listinfo/zope Developers: https://mail.zope.org/mailman/listinfo/zope-dev ) --===============6055500738027040851==--