[Zope-Annce] SECURITY alert and hotfix release...
Fri, 23 Feb 2001 17:33:23 -0500
Casey Duncan uncovered a potential security issue today that
necessitated a hotfix release.
This hotfix addresses an important security issue that affects Zope
versions up to and including Zope 2.3.1 b1.
The issue is related to ZClasses in that a user with through-the-web
scripting capabilities on a Zope site can view and assign class attributes
to ZClasses, possibly allowing them to make inappropriate changes to
This patch also fixes problems in the ObjectManager, PropertyManager, and
PropertySheet classes related to mutability of method return values which
could be perceived as a security problem.
We *highly* recommend that any Zope site running versions of
Zope up to and including 2.3.1 b1 have this hotfix product installed
to mitigate these issues if the site is accessible by untrusted users
who have through-the-web scripting privileges.
Brian Lloyd email@example.com
Software Engineer 540.371.6909
Digital Creations http://www.digicool.com