PyPI: zope2

CVE-2000-1212

Safety vulnerability ID: SFTY-20001218-92437

Safety legacy ID: pyup.io-61232

Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.

Created at: Apr 16, 2026Updated at: Apr 16, 2026

Overview

Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.

Advisory

Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.

Affected Package

Affecting zope2 package, versions
>=2.2.1b1,<=2.2.4

Also affects

---

How to Fix

Upgrade
zope2
to
2.12.0a1
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more