Safety vulnerability ID: 38035
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Products.dcworkflow before 2.1.0beta2 has a vulnerability because it includes the Zope dependency version <2.10.2, which has an injection vulnerability. See: CVE-2007-0240.
Latest version: 2.3.0
DCWorkflow product for the Zope Content Management Framework
------------------------
- moved the Zope dependency to version 2.10.4
- Remove antique usage of marker attributes in favor of interfaces,
leaving BBB behind for places potentially affecting third-party code.
(http://www.zope.org/Collectors/CMF/440)
- Add POST-only protections to security critical methods.
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0240)
- Workflow definition instances now have a description field
(http://www.zope.org/Collectors/CMF/480)
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application