CVE-2021-32633
Remote Code Execution via traversal in TAL expressions
描述
Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules indirectly through Python modules that are available for direct use. By default, only users with the Manager role can add or edit Zope Page Templates through the web, but sites that allow untrusted users to add/edit Zope Page Templates through the web are at risk from this vulnerability. The problem has been fixed in Zope 5.2 and 4.6. As a workaround, a site administrator can restrict adding/editing Zope Page Templates through the web using the standard Zope user/role permission mechanisms. Untrusted users should not be assigned the Zope Manager role and adding/editing Zope Page Templates through the web should be restricted to trusted users only.
如何修補 CVE-2021-32633
要修補 CVE-2021-32633,請將受影響套件升級到下列已修補版本。
- —升級至 4.6 或更新版本
- —升級至 4.6 或更新版本
- —升級至 1f8456bf1f908ea46012537d52bd7e752a532c91 或更新版本
CVE-2021-32633 正在被利用嗎?
低 — EPSS 為 1.8%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 4.6
- from 0, < 4.6
- from 0, < 1f8456bf1f908ea46012537d52bd7e752a532c91 | from 0, < 4.6, >= 5.0, < 5.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM6.8 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |