Medium severity6.5NVD Advisory· Published Mar 8, 2021· Updated Jun 17, 2026
CVE-2021-21336
CVE-2021-21336
Description
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an information disclosure vulnerability - everyone can list the names of roles defined in the ZODB Role Manager plugin if the site uses this plugin. The problem has been fixed in version 2.6.0. Depending on how you have installed Products.PluggableAuthService, you should change the buildout version pin to 2.6.0 and re-run the buildout, or if you used pip simply do pip install "Products.PluggableAuthService>=2.6.0".
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Products.PluggableAuthServicePyPI | < 2.6.0 | 2.6.0 |
Affected products
4- cpe:2.3:a:zope:products.pluggableauthservice:*:*:*:*:*:*:*:*Range: <2.6.0
- zopefoundation/Products.PluggableAuthServicev5Range: < 2.6.0
Patches
Vulnerability mechanics
References
9- github.com/zopefoundation/Products.PluggableAuthService/commit/2dad81128250cb2e5d950cddc9d3c0314a80b4bbnvdPatchThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2021/05/21/1nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2021/05/22/1nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-p75f-g7gx-2r7pghsaADVISORY
- github.com/zopefoundation/Products.PluggableAuthService/security/advisories/GHSA-p75f-g7gx-2r7pnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-21336ghsaADVISORY
- pypi.org/project/Products.PluggableAuthService/nvdProductThird Party Advisory
- github.com/pypa/advisory-database/tree/main/vulns/products-pluggableauthservice/PYSEC-2021-44.yamlghsaWEB
- pypi.org/project/Products.PluggableAuthServiceghsaWEB
News mentions
0No linked articles in our index yet.