Zope Products.PluggableAuthService 2.6.0

CPE Details

Zope Products.PluggableAuthService 2.6.0
2.6.0
2021-03-09
11h35 +00:00
2021-04-05
14h01 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:zope:products.pluggableauthservice:2.6.0:*:*:*:*:*:*:*

Informations

Vendor

zope

Product

products.pluggableauthservice

Version

2.6.0

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2021-21337 2021-03-08 20h10 +00:00 Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an open redirect vulnerability. A maliciously crafted link to the login form and login functionality could redirect the browser to a different website. The problem has been fixed in version 2.6.1. Depending on how you have installed Products.PluggableAuthService, you should change the buildout version pin to `2.6.1` and re-run the buildout, or if you used `pip` simply do `pip install "Products.PluggableAuthService>=2.6.1".
6.1
Moyen