App.Undo.UndoSupport.get_request_var_or_attr exposes attributes

Bug #1079238 reported by Tres Seaver
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Zope 2
Fix Released
Undecided
Unassigned

Bug Description

Historical bug: prior to r123753 (2.12 branch) and forward-ports, the
'get_request_far_or_attr' helper function of App.Undo.UndoSupport
could be abused to gain access to protected attributes of the context.

Fix released 2011-12-12 with 2.12.21 and 2.13.11

CVE References

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.