涉及程序:
Zope 2.1.7 以下版本
描述:
Zope 2.1.7 以下版本存在安全问题
详细:
Zope 是一个 Http 服务软件。Zope 2.1.7 以下版本存在安全问题,这个问题是对 DocumentTemplate package 内的一个基本类中缺少足够的安全保护,这会导致不强制用户的认证就可以通过 TML 代码远程地修改 DTMLDocuments or DTMLMethods 的内容。
这个软件最新版本是 Zope 2.2 Beta 1 但还有这个问题,也许在 Zope 2.2 Beta 2 中会修正。
> A patch is also available if it is not feasible to update your
> Zope installation at this time (the patch is based on 2.1.6):
>
> http://www.zope.org/Products/Zope/2.1.7/DT_String.diff
>
> If you are evaluating any of the recent 2.2 alpha or beta releases,
> you should apply the patch noted above if your site is accessible
> by untrusted clients. A forthcoming 2.2 beta 2 release will contain feedom.net
> the fix for this issue.
>
> While we know of no instances of this issue being used to exploit a
> site, we *highly* recommend that any Zope site that is accessible by
> untrusted clients take the appropriate mitigation steps immediately.
解决方案:
使用补丁
