Access control vulnerable to user data deletion by anonynmous users
Moderate severity
GitHub Reviewed
Published
Nov 4, 2024
in
zopefoundation/AccessControl
•
Updated Nov 7, 2024
Description
Published by the National Vulnerability Database
Nov 4, 2024
Published to the GitHub Advisory Database
Nov 4, 2024
Reviewed
Nov 4, 2024
Last updated
Nov 7, 2024
Impact
Anonymous users can delete the user data maintained by an
AccessControl.userfolder.UserFolder
which may prevent any privileged access.Patches
The problem is fixed in version 7.2.
Workarounds
The problem can be fixed by adding
data__roles__ = ()
toAccessControl.userfolder.UserFolder
.References
zopefoundation/AccessControl#159
References