Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violation of the intended configuration.
| Software | From | Fixed in |
|---|---|---|
| zope / zope | 2.4.0 | 2.4.0.x |
| zope / zope | 2.2.1 | 2.2.1.x |
| zope / zope | 2.3.1 | 2.3.1.x |
| zope / zope | 2.4.4b1 | 2.4.4b1.x |
| zope / zope | 2.2.0 | 2.2.0.x |
| zope / zope | 2.3.2 | 2.3.2.x |
| zope / zope | 2.5.1b1 | 2.5.1b1.x |
| zope / zope | 2.5.0 | 2.5.0.x |
| zope / zope | 2.4.1 | 2.4.1.x |
| zope / zope | 2.2.4 | 2.2.4.x |
| zope / zope | 2.4.2 | 2.4.2.x |
| zope / zope | 2.4.3 | 2.4.3.x |
| zope / zope | 2.2.2 | 2.2.2.x |
| zope / zope | 2.2.5 | 2.2.5.x |
| zope / zope | 2.3.0 | 2.3.0.x |
| zope / zope | 2.3.3 | 2.3.3.x |
| zope / zope | 2.2.3 | 2.2.3.x |