CVE-2024-51734
Impact
Anonymous users can delete the user data maintained by an AccessControl.userfolder.UserFolder which may prevent any privileged access.
Patches
The problem is fixed in version 7.2.
Workarounds
The problem can be fixed by adding dataroles = () to AccessControl.userfolder.UserFolder.
References
https://github.com/zopefoundation/AccessControl/issues/159
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/zopefoundation/AccessControl/security/advisories/GHSA-g5vw-3h65-2q3v, https://nvd.nist.gov/vuln/detail/CVE-2024-51734, https://github.com/zopefoundation/AccessControl/issues/159, https://github.com/zopefoundation/AccessControl, https://pypi.org/project/zope, https://github.com/advisories/GHSA-g5vw-3h65-2q3v