Zope AccessControl 为在 Zope 中使用提供了一种通用的安全框架。在 7.4 版本之前,允许不受信任的用户创建并执行由 AccessControl 控制的 Python 代码的应用程序,在通过 str 子类访问时,未能安全地保护 和 方法。在 和 中,Python 格式化操作可通过无限制的 和 行为递归地访问属性和订阅,而不是使用策略受限的 和 操作。因此,受控的格式化字符串可能会泄露可通过格式化操作访问到的对象。该问题已在 7.4 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zopefoundation | AccessControl | < 7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet