SCA: security update for Zope (GHSA-5pr9-v234-jw36)

high Tenable Cloud Security Plugin ID 410964

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access
untrusted modules indirectly through Python modules that are available for direct use. By default, only
users with the Manager role can add or edit Zope Page Templates through the web, but sites that allow
untrusted users to add/edit Zope Page Templates through the web are at risk from this vulnerability. The
problem has been fixed in Zope 5.2 and 4.6. As a workaround, a site administrator can restrict
adding/editing Zope Page Templates through the web using the standard Zope user/role permission
mechanisms. Untrusted users should not be assigned the Zope Manager role and adding/editing Zope Page
Templates through the web should be restricted to trusted users only. (CVE-2021-32633)

See Also

https://github.com/advisories/GHSA-5pr9-v234-jw36

Plugin Details

Severity: High

ID: 410964

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2021-32633

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7.6

Threat Score: 6.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/18/2021

Vulnerability Publication Date: 5/21/2021

Reference Information

CVE: CVE-2021-32633

cwe: CWE-22