The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| zope(PyPI) | 2.0.0 | 2.4.4b2 | N/A |
| zope(PyPI) | 2.5.0 | 2.5.1b2 | N/A |
CVSS Metrics