Zope 4.6.3 and 5.3 released with a security fix
Jens Vagelpohl via Zope-Announce <[email protected]> Sat, 31 Jul 2021 11:55:20 +0200
| Newsgroups | gmane.comp.web.zope.announce,gmane.comp.web.zope.general |
|---|---|
| Message-ID | <[email protected]> |
--===============3815275749978118984== Content-Type: multipart/signed; boundary="Apple-Mail=_5DDD4CFB-A7D6-4656-88F1-C701DFA80CBB"; protocol="application/pgp-signature"; micalg=pgp-sha512 --Apple-Mail=_5DDD4CFB-A7D6-4656-88F1-C701DFA80CBB Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 On behalf of Zope developer community I am pleased to announce the = releases of Zope 4.6.3 and 5.3. This bugfix release solves a few minor issues and contains a security = fix. For the full list of changes see the change logs at = https://zope.readthedocs.io/en/4.x/changes.html#id1 and = https://zope.readthedocs.io/en/latest/changes.html#id1 Installation instructions can be found at = https://zope.readthedocs.io/en/4.x/INSTALL.html and = https://zope.readthedocs.io/en/latest/INSTALL.html. These releases contain a security fix that prevents remote code = execution through Script (Python) objects. You are only at risk if all = of the following are true: - You use Python 3 for your Zope deployment (Zope 4 on Python 2 is not = affected) - You run Zope 4 below version 4.6.3 or Zope 5 below version 5.3 - You have installed the optional Products.PythonScripts add-on package - You allow untrusted non-admin users to add or edit Script (Python) = objects By default, untrusted non-admin users cannot add or edit Script (Python) = objects, only =E2=80=9CManager=E2=80=9D users can. Enabling this level = of access for untrusted users would be a very unusual configuration and = it is highly unlikely any site administrator would do so to begin with. The related security advisories with full details are published here: - = https://github.com/zopefoundation/Zope/security/advisories/GHSA-g4gq-j4p2-= j8fr - = https://github.com/zopefoundation/AccessControl/security/advisories/GHSA-q= cx9-j53g-ccgf NOTE FOR PLONE USERS: Make sure to install the latest version of = PloneHotfix20210518 first, which should appear shortly after this Zope = release. See https://plone.org/security/hotfix/20210518. Don't install = Zope 4.6.3 or 5.3 into an existing Plone setup without testing. The = PloneHotfix packages ensures that the Zope changes don=E2=80=99t = interfere with Plone add-ons. Jens Vagelpohl --Apple-Mail=_5DDD4CFB-A7D6-4656-88F1-C701DFA80CBB Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=signature.asc Content-Type: application/pgp-signature; name=signature.asc Content-Description: Message signed with OpenPGP -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEci4R3bPsmS6uSKPIwbdNWZil9lcFAmEFHggACgkQwbdNWZil 9ldtiBAAulD5qBvwSub0zqi9l3nrdxhiERmWuyQ7tp4RXg4Mq/DgXJvmnZ9lmay5 DlFwVtXv7bdk5k+vteqkkfHOJwT5P6RTI1KDz1kI6WbhnpRud3WeTBzQphB3fL9S VUQ+4vCDSxUld7kt5+Ghmn/K3/TET1Mee2Y+yxXefXpI80RupMKjMqO2BJtNb5n+ pgS2mmnGABBvZSGQfiUgFqcfc3vjpgLeFVyjt28YMTMMtTrddQBBpwtfwk1ZSGC1 C/D6Hc7LbJD6PZquMJSUgCvjO/pKnEPsNyQYEd9CUyewOAND8Xv50+Odnm+QuOQF wu2+YYBGvmGOogA5lKK96LAnl0XlK9VHuHbqmCmTo403dXwSoDuUmCabonYol99r 3M0WvNPV8ZkC/KA5dnjK7VnPxmR5EuHnwuhTBWKC0EGGLwYzoUaD9hmUyjU1I7hp omL33sUpizhTHLfYxwt4T5GM/zX1Pla058NFiU5au3F/TyLk1HvJ1/5OgWg+bt5j AphugCoIxYCmjm7sO5PR26RTu36HNi9f25v/LCa0szweQ/lpdH28TpDUnix7NKge 4rx1SfGqHttotQ11gwxxEcZU9NUuJF5XC2rQotnzcT1jDGWbi2yQcRhQ8/tWExH+ R4oCHCl372tkgRuKDyT0lPbE2VPEHdLDc7ONcCd2dHJ/3pb0PVs= =Zhwe -----END PGP SIGNATURE----- --Apple-Mail=_5DDD4CFB-A7D6-4656-88F1-C701DFA80CBB-- --===============3815275749978118984== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Zope-Announce maillist - [email protected] https://mail.zope.org/mailman/listinfo/zope-announce Zope-Announce for Announcements only - no discussions (Related lists - Users: https://mail.zope.org/mailman/listinfo/zope Developers: https://mail.zope.org/mailman/listinfo/zope-dev ) --===============3815275749978118984==--