Page Template source not protected adequately
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Zope 2 |
Fix Released
|
Medium
|
Tres Seaver | ||
Zope CMF buildout |
Triaged
|
Low
|
Unassigned |
Bug Description
Both Products.
'source_dot_xml',
'source.xml',
'source.html'
These are publishable to any user, without any authentication.
e.g. http://
I had a go at CVSSing this, though it's my first time so might be worth checking...
CVSS Base Score
5 (AV:N/AC:
Impact Subscore
2.9
Exploitability Subscore
10
CVSS Temporal Score
Undefined
CVSS Environmental Score
3.9 (CDP:N/
Overall CVSS Score
3.9
Vector: (AV:N/AC:
To put a smile on your face, the 'Src' class, an instance of which is assigned to these attributes, has the ironic docstring:
""" I am scary code """
Changed in zope2: | |
importance: | Undecided → Medium |
status: | New → Confirmed |
Changed in zope2: | |
status: | Confirmed → Fix Released |
information type: | Private Security → Public Security |
Environmental scores aren't set by the vendor:
CVSS Base Score
5
Impact Subscore
2.9
Exploitability Subscore
10
CVSS Temporal Score
Undefined
CVSS Environmental Score
Undefined
Overall CVSS Score
5
(AV:N/AC: L/Au:N/ C:P/I:N/ A:N)
When we release patches that gets multiplied by 0.74 for the temporal score, but the base score is almost always 5.