---
id: CVE-2000-1211
aliases:
  - GHSA-h2xh-jvpf-xq42
  - PYSEC-2026-759
title: Zope does not properly perform security registration for legacy names
summary: Zope does not properly perform security registration for legacy names
severity: high
vendor: zope
product: zope
ecosystem: pip
affected:
  - 'zope >= 2.2.0, <= 2.2.4'
published: '2022-04-30'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-h2xh-jvpf-xq42'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2000-1211'
  - url: >-
      https://web.archive.org/web/20010910131909/http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-083.php3
  - url: >-
      https://web.archive.org/web/20021227061438/http://www.iss.net/security_center/static/5824.php
  - url: 'http://www.redhat.com/support/errata/RHSA-2000-125.html'
  - url: 'http://www.zope.org/Products/Zope/Hotfix_2000-12-08/security_alert'
tags:
  - osv
  - pip
epss: 0.01439
epssPercentile: 0.71583
ingestedAt: '2026-07-08T18:25:49.968Z'
---

## Overview

Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.

## Affected packages

- `zope >= 2.2.0, <= 2.2.4`

## Remediation

Refer to the advisory for the patched release.
