High severityNVD Advisory· Published Dec 16, 2000· Updated Apr 16, 2026
CVE-2000-1211
CVE-2000-1211
Description
Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
zopePyPI | >= 2.2.0, <= 2.2.4 | — |
Affected products
12cpe:2.3:a:zope:zope:2.2.0:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:zope:zope:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:zope:zope:2.2.0a1:*:*:*:*:*:*:*
- cpe:2.3:a:zope:zope:2.2.0b1:*:*:*:*:*:*:*
- cpe:2.3:a:zope:zope:2.2.0b2:*:*:*:*:*:*:*
- cpe:2.3:a:zope:zope:2.2.0b3:*:*:*:*:*:*:*
- cpe:2.3:a:zope:zope:2.2.0b4:*:*:*:*:*:*:*
- cpe:2.3:a:zope:zope:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:zope:zope:2.2.1b1:*:*:*:*:*:*:*
- cpe:2.3:a:zope:zope:2.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:zope:zope:2.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:zope:zope:2.2.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.linux-mandrake.com/en/security/2000/MDKSA-2000-083.php3nvdPatchVendor Advisory
- www.zope.org/Products/Zope/Hotfix_2000-12-08/security_alertnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-h2xh-jvpf-xq42ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2000-1211ghsaADVISORY
- www.redhat.com/support/errata/RHSA-2000-125.htmlnvdWEB
- web.archive.org/web/20010910131909/http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-083.php3ghsaWEB
- web.archive.org/web/20021227061438/http://www.iss.net/security_center/static/5824.phpghsaWEB
- www.iss.net/security_center/static/5824.phpnvd
- www.osvdb.org/6282nvd
News mentions
0No linked articles in our index yet.