{"id":"GHSA-jcjp-qqpq-pc54","summary":"Zope allows local users to read arbitrary files","details":"Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the \"raw\" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.","aliases":["CVE-2006-3458"],"modified":"2024-11-22T04:59:46.825660Z","published":"2022-05-01T07:09:18Z","database_specific":{"nvd_published_at":"2006-07-07T23:05:00Z","cwe_ids":[],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2024-11-21T22:13:08Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3458"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27636"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/zope2/PYSEC-2006-7.yaml"},{"type":"PACKAGE","url":"https://github.com/zopefoundation/Zope"},{"type":"WEB","url":"https://usn.ubuntu.com/317-1"},{"type":"WEB","url":"http://mail.zope.org/pipermail/zope-announce/2006-July/001984.html"},{"type":"WEB","url":"http://www.debian.org/security/2006/dsa-1113"},{"type":"WEB","url":"http://www.novell.com/linux/security/advisories/2006_19_sr.html"}],"affected":[{"package":{"name":"zope2","ecosystem":"PyPI","purl":"pkg:pypi/zope2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.7.0"},{"fixed":"2.7.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jcjp-qqpq-pc54/GHSA-jcjp-qqpq-pc54.json"}},{"package":{"name":"zope2","ecosystem":"PyPI","purl":"pkg:pypi/zope2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.8.0"},{"fixed":"2.8.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jcjp-qqpq-pc54/GHSA-jcjp-qqpq-pc54.json"}},{"package":{"name":"zope2","ecosystem":"PyPI","purl":"pkg:pypi/zope2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.9.0"},{"fixed":"2.9.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jcjp-qqpq-pc54/GHSA-jcjp-qqpq-pc54.json"}}],"schema_version":"1.9.0"}