CVE ID | |
CVSS SCORE | 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
AFFECTED VENDORS |
Zope |
AFFECTED PRODUCTS |
Zope |
VULNERABILITY DETAILS |
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Zope Application Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the contentFilter class. The issue results from uncontrolled resource consumption. An attacker can leverage this vulnerability to create a denial-of-service condition on the server. |
ADDITIONAL DETAILS |
07/13/23 – ZDI reported the vulnerability to the vendor -- Mitigation: Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the application. |
DISCLOSURE TIMELINE |
|
CREDIT | Anonymous |