|
Zope contains a flaw that may allow a malicious user to gain access to files outside the configured security context. The issue is due to Zope failing to honour the security context of the creator of a proxy role when determining access to an object via that role. This flaw may lead to a loss of confidentiality.
|