'map' builtin not being properly guarded

Bug #282677 reported by Sidnei da Silva
266
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Zope 2
Fix Released
High
Sidnei da Silva

Bug Description

The 'guarded_map' implementation provided by ZopeGuards does not properly check item access. Actually, it is checking item access of the provided list of arguments but not the item access of each of the arguments.

Revision history for this message
Sidnei da Silva (sidnei) wrote :

Here's a patch that applies to this bug and also to #282678

Revision history for this message
Andreas Jung (ajung) wrote :

Could you please commit the fix ?

Changed in zope2:
assignee: nobody → sidnei
importance: Undecided → High
Revision history for this message
Sidnei da Silva (sidnei) wrote :

All the way back to Zope 2.9? Is that what you want??

Revision history for this message
Andreas Jung (ajung) wrote :

yes please

Revision history for this message
Andreas Jung (ajung) wrote :

Sidnei committed the patch but did not close the ticket.

Changed in zope2:
status: New → Fix Released
information type: Private Security → Public Security
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.