Safety vulnerability ID: 61581
The information on this page was manually curated by our Cybersecurity Intelligence Team.
[This advisory has been limited. Please create a free account to view the full advisory.]
Latest version: 5.13
Zope application server / web framework
[This affected versions has been limited. Please create a free account to view the full affected versions.]
[This fixed versions has been limited. Please create a free account to view the full fixed versions.]
------------------
- Make sure the object title in the ZMI breadcrumbs is quoted
to prevent a cross-site scripting issue.
- Update to newest compatible versions of dependencies.
- Base the inline/attachment logic developed for CVE-2023-42458
on the media type proper (ignore parameters and
whitespace and normalize to lowercase)
(`1167 <https://github.com/zopefoundation/Zope/pull/1167>`_).
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application