GHSA-m52m-2qpx-9j4j

Suggest an improvement
Source
https://github.com/advisories/GHSA-m52m-2qpx-9j4j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-m52m-2qpx-9j4j/GHSA-m52m-2qpx-9j4j.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-m52m-2qpx-9j4j
Aliases
Published
2022-05-02T03:37:58Z
Modified
2024-11-30T05:26:57.828031Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N CVSS Calculator
Summary
Zope Object Database (ZODB) Arbitrary files reading and deletion
Details

Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x before 3.9.0c2, when certain ZEO database sharing and blob support are enabled, allows remote authenticated users to read or delete arbitrary files via unknown vectors.

Database specific
{
    "nvd_published_at": "2009-09-08T18:30:00Z",
    "cwe_ids": [],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2024-04-22T18:59:10Z"
}
References

Affected packages

PyPI / zodb3

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.8
Fixed
3.8.3

Affected versions

3.*

3.8.0
3.8.1b1
3.8.1b2
3.8.1b3
3.8.1b4
3.8.1b5
3.8.1b6
3.8.1b7
3.8.1b8
3.8.1b9
3.8.1
3.8.2
3.8.3b1

PyPI / zodb3

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.9a0
Fixed
3.9.0c2

Affected versions

3.*

3.9.0a1
3.9.0a2
3.9.0a3
3.9.0a4
3.9.0a5
3.9.0a6
3.9.0a7
3.9.0a9
3.9.0a10
3.9.0a11
3.9.0a12
3.9.0b1
3.9.0b2
3.9.0b3
3.9.0b4
3.9.0b5
3.9.0c1