id: PYSEC-2023-193 modified: 2023-10-10T20:21:16.174482Z published: 2023-10-04T21:15:00Z aliases: - CVE-2023-44389 - GHSA-m755-gxxg-r5qh details: Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store script code that is executed while viewing the affected object in the Zope Management Interface (ZMI). All versions of Zope 4 and Zope 5 are affected. Patches will be released with Zope versions 4.8.11 and 5.8.6 affected: - package: ecosystem: PyPI name: zope purl: pkg:pypi/zope ranges: - type: GIT events: - introduced: "0" - fixed: aeaf2cdc80dff60815e3706af448f086ddc3b98d - fixed: 21dfa78609ffd8b6bd8143805678ebbacae5141a repo: https://github.com/zopefoundation/Zope - type: ECOSYSTEM events: - introduced: "5.0" - fixed: 5.8.6 - introduced: "4.0" - fixed: 4.8.11 versions: - "4.0" - "4.1" - 4.1.1 - 4.1.2 - 4.1.3 - "4.2" - 4.2.1 - "4.3" - "4.4" - 4.4.1 - 4.4.2 - 4.4.3 - 4.4.4 - "4.5" - 4.5.1 - 4.5.2 - 4.5.3 - 4.5.4 - 4.5.5 - "4.6" - 4.6.1 - 4.6.2 - 4.6.3 - "4.7" - "4.8" - 4.8.1 - 4.8.10 - 4.8.2 - 4.8.3 - 4.8.4 - 4.8.5 - 4.8.6 - 4.8.7 - 4.8.8 - 4.8.9 - "5.0" - "5.1" - 5.1.1 - 5.1.2 - "5.2" - 5.2.1 - "5.3" - "5.4" - "5.5" - 5.5.1 - 5.5.2 - "5.6" - "5.7" - 5.7.1 - 5.7.2 - 5.7.3 - "5.8" - 5.8.1 - 5.8.2 - 5.8.3 - 5.8.4 - 5.8.5 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N references: - type: ADVISORY url: https://github.com/zopefoundation/Zope/security/advisories/GHSA-m755-gxxg-r5qh - type: FIX url: https://github.com/zopefoundation/Zope/commit/aeaf2cdc80dff60815e3706af448f086ddc3b98d - type: FIX url: https://github.com/zopefoundation/Zope/commit/21dfa78609ffd8b6bd8143805678ebbacae5141a