GHSA-vwrc-g9q6-f675

Suggest an improvement
Source
https://github.com/advisories/GHSA-vwrc-g9q6-f675
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-vwrc-g9q6-f675/GHSA-vwrc-g9q6-f675.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vwrc-g9q6-f675
Aliases
Published
2022-04-30T18:19:43Z
Modified
2026-07-06T08:11:13Z
Summary
Zope Server vulnerable to DoS via header injection
Details

Zope is a Web application server for Linux. Zope versions 2.0 through 2.5.1 b1 are vulnerable to a denial of service attack, caused by a vulnerability that occurs when using the "through the Web code" capability. A remote attacker could inject malicious headers into a response to cause the vulnerable system to crash.

Database specific
{
    "cwe_ids":  [
        "CWE-400"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-02-12T18:04:43Z",
    "nvd_published_at":  "2002-07-23T04:00:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

PyPI / zope

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.4.4b2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-vwrc-g9q6-f675/GHSA-vwrc-g9q6-f675.json"

PyPI / zope

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.5.0
Fixed
2.5.1b2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-vwrc-g9q6-f675/GHSA-vwrc-g9q6-f675.json"