Re: [Zope] Hotfix for security vulnerability

yuppie <[email protected]>
Newsgroups gmane.comp.web.zope.devel
Message-ID <[email protected]>
Laurence Rowe wrote:
>> This hotfix addresses a serious vulnerability in the Zope2
>> application server.  Affected versions of Zope2 include:
>>
>> - - 2.12.x<= 2.12.20
>>
>> - - 2.13.x<= 2.13.6
>>
>> Older releases (2.11.x, 2.10.x, etc.) are not vulnerable.
>
> Can you confirm whether or not Zope 2.13.6 through 2.13.10 are affected?

They are affected. "2.13.6" seems to be a typo. But AFAICT Plone is not 
affected because it doesn't use the default user folder implementation 
shipped with Zope.

Cheers, Yuppie
_______________________________________________
Zope-Dev maillist  -  [email protected]
https://mail.zope.org/mailman/listinfo/zope-dev
**  No cross posts or HTML encoding!  **
(Related lists - 
 https://mail.zope.org/mailman/listinfo/zope-announce
 https://mail.zope.org/mailman/listinfo/zope )
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.