CVE-2009-0669Improper Authentication in Zodb

Severity
7.5HIGHNVD
EPSS
0.5%
top 32.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 7
Latest updateMay 2

Description

Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass authentication via vectors involving the ZEO network protocol.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDzope/zodb3.8.1+2

Patches

🔴Vulnerability Details

3
GHSA
Zope Object Database (ZODB) Authentication bypass in ZEO storage servers2022-05-02
OSV
Zope Object Database (ZODB) Authentication bypass in ZEO storage servers2022-05-02
OSV
CVE-2009-0669: Zope Object Database (ZODB) before 32009-08-07

📋Vendor Advisories

2
Ubuntu
Zope vulnerabilities2009-10-14
Red Hat
zope: ZEO authentication bypass2009-08-06

💬Community

2
Bugzilla
CVE-2009-0668 zope: ZEO arbitrary Python code execution in the context of server process2009-07-23
Bugzilla
CVE-2009-0669 zope: ZEO authentication bypass2009-07-23