GHSA-g5vw-3h65-2q3v
GitHub Security Advisory
Access control vulnerable to user data deletion by anonynmous users
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
### Impact
Anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access.
### Patches
The problem is fixed in version 7.2.
### Workarounds
The problem can be fixed by adding `data__roles__ = ()` to `AccessControl.userfolder.UserFolder`.
### References
https://github.com/zopefoundation/AccessControl/issues/159
Affected Packages
PyPI
AccessControl
Affected versions:
0
(fixed in 7.2)
PyPI
Zope
Affected versions:
0
(fixed in 5.11.1)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 12, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.