Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.
| Software | From | Fixed in |
|---|---|---|
| zope / zope | 2.2.0b2 | 2.2.0b2.x |
| zope / zope | 2.2.1 | 2.2.1.x |
| zope / zope | 2.2.0b4 | 2.2.0b4.x |
| zope / zope | 2.2.0 | 2.2.0.x |
| zope / zope | 2.2.1b1 | 2.2.1b1.x |
| zope / zope | 2.2.4 | 2.2.4.x |
| zope / zope | 2.2.2 | 2.2.2.x |
| zope / zope | 2.2.0b1 | 2.2.0b1.x |
| zope / zope | 2.2.0b3 | 2.2.0b3.x |
| zope / zope | 2.2.0a1 | 2.2.0a1.x |
| zope / zope | 2.2.3 | 2.2.3.x |