Zope 4.6.1 and 5.2.1 released with an important security fix

Jens Vagelpohl <[email protected]> Tue, 8 Jun 2021 10:46:35 +0200
Newsgroups gmane.comp.web.zope.announce,gmane.comp.web.zope.general
Message-ID <[email protected]>
--===============6055500738027040851==
Content-Type: multipart/signed;
	boundary="Apple-Mail=_920C9A39-6810-45AF-B960-CB0C1734A8A0";
	protocol="application/pgp-signature";
	micalg=pgp-sha512


--Apple-Mail=_920C9A39-6810-45AF-B960-CB0C1734A8A0
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

On behalf of Zope developer community I am pleased to announce the =
releases of Zope 4.6.1 and 5.2.1.

This bugfix release solves a few minor issues and also contains an =
important security fix, see below. For the full list of changes see the =
change logs at https://zope.readthedocs.io/en/4.x/changes.html#id1 and =
https://zope.readthedocs.io/en/latest/changes.html#id1

Installation instructions can be found at =
https://zope.readthedocs.io/en/4.x/INSTALL.html and =
https://zope.readthedocs.io/en/latest/INSTALL.html.

NOTE: These releases contain an expanded security fix that prevents =
remote code execution through TAL expressions. The first iteration of =
the security fix in Zope 4.6 and 5.2 did not catch all cases of =
unauthorized TAL path expression traversal. Just like the first fix, you =
will only ever be at risk if you allow untrusted users to add or edit =
Zope Page Template objects, which is a very unusual non-standard site =
configuration. For more details, see the security advisory at =
https://github.com/zopefoundation/Zope/security/advisories/GHSA-rpcg-f9q6-=
2mq6. A CVE has been requested through GitHub.

NOTE FOR PLONE USERS: Make sure to install the latest version of =
PloneHotfix20210518 first, which should appear shortly after this Zope =
release. See https://plone.org/security/hotfix/20210518. Don't install =
Zope 4.6.1 or 5.2.1 into an existing Plone setup without testing. The =
security changes in Zope break some Plone add-ons that relied on the old =
insecure traversal behavior. PloneHotfix20210518 ensures support for =
those Plone add-ons.

Jens Vagelpohl


--Apple-Mail=_920C9A39-6810-45AF-B960-CB0C1734A8A0
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEci4R3bPsmS6uSKPIwbdNWZil9lcFAmC/LmsACgkQwbdNWZil
9lfTOg/+IwxZ7HbSRPWINM06dzonHSx3wezJaF1h456tLJpvD5krOt3bOnwuICxz
Cix85SzuEb3mte/bEs7B6T4VXkCgG+gtmyPRPtIM/smRWkVqScAZSL3dtS5e+4Vy
NPl47HiunJZP/k2Z5OBPsve593DPqNaBK6ubgoiO7o+g1UEKXANiz0UtIh7n15cJ
yqTxB/SY4Py/3J4gLuem6uNggZMs0Qvo3iXdmgLiFfOGRvRbFj9bVwEwL+hAgtew
30ddmBscpez/tqYyNCfJKUIIEVRJwyndAlrtQcLfONE2nKKYpdyal5DiZi4GYiJl
PNR6u+0dps5qKoTAxbTnFW1cGg2+EMhDAxjTxD9fmXeaa/Os4DgCQ/DBGPhUCKs3
NAOHJdBTGuVEWv9ggf4x6f00/A3Wm2XHdU41HmJG4yQCghSrrbDgvBmBji1guREn
G7V6yxJlv4eO3zd55K7SpKuHvUmzqVHgwxiR+5u5/0um3RYcdIGdvUojh6S7hlz1
W+dcYnHWtbooBYZNnH9mJousIoUkSdjtKVRCIq+OEJLhj7UKFDluiaK0xadbFa+p
HE2Mm1kp0AQrAN0JgZhBNbZ4vKFWC73v1lPbi36zxpOJIuOBxwzt2GM9Vjy+JDTP
/t9ZTmjGAukc9KHa/q5XJ6p/5l7xTsTeyCknFPTm8b83kEuu4ic=
=Z6oj
-----END PGP SIGNATURE-----

--Apple-Mail=_920C9A39-6810-45AF-B960-CB0C1734A8A0--

--===============6055500738027040851==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Zope-Announce maillist  -  [email protected]
https://mail.zope.org/mailman/listinfo/zope-announce

  Zope-Announce for Announcements only - no discussions

(Related lists -
 Users: https://mail.zope.org/mailman/listinfo/zope
 Developers: https://mail.zope.org/mailman/listinfo/zope-dev )

--===============6055500738027040851==--