CVE-2000-1211
Zope does not properly perform security registration for legacy names
EPSS 0.60%
Description
Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.
How to fix CVE-2000-1211
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- PyPI/zope—no fix listed
Is CVE-2000-1211 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 2.2.0, <= 2.2.4