CVE-2009-0669

HIGH7.5EPSS 0.65%

Zope Object Database (ZODB) Authentication bypass in ZEO storage servers

發布日:2022/5/2修改日:2024/11/19
也稱為:GHSA-5432-c996-hvhjPYSEC-2009-9

描述

Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass authentication via vectors involving the ZEO network protocol.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:L/SA:N
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

參考連結(11)