CVE-2002-0688
ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions
EPSS 0.60%
Description
ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.
How to fix CVE-2002-0688
To remediate CVE-2002-0688, upgrade the affected package to a fixed version below.
- Debian/zope—upgrade to 2.5.1-1woody1 or later
- PyPI/zope—upgrade to 2.6.0 or later
Is CVE-2002-0688 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.5.1-1woody1
- >= 2.4.0, < 2.6.0
References (6)
- ADVISORYnvd.nist.gov/vuln/detail/CVE-2002-0688
- WEBweb.archive.org/web/20020810160608/http://www.zope.org/Products/Zope/Hotfix_2002-06-14/security_alert
- WEBweb.archive.org/web/20020822025750/http://www.iss.net/security_center/static/9610.php
- WEBweb.archive.org/web/20021206023914/http://rhn.redhat.com/errata/RHSA-2002-060.html