---
id: CVE-2002-0170
aliases:
  - GHSA-c3rp-4cjh-cp38
  - PYSEC-2026-758
title: Zope does not properly verify the access for objects with proxy roles
summary: Zope does not properly verify the access for objects with proxy roles
severity: high
vendor: zope
product: zope
ecosystem: pip
affected:
  - 'zope >= 2.2.0, < 2.4.4'
  - 'zope >= 2.5.0, < 2.5.1'
patched:
  - zope 2.4.4
  - zope 2.5.1
published: '2022-04-30'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-c3rp-4cjh-cp38'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2002-0170'
  - url: 'https://github.com/zopefoundation/Zope'
  - url: 'https://launchpad.net/zope2/+milestone/2.4.4'
  - url: 'https://launchpad.net/zope2/+milestone/2.5.1'
  - url: >-
      https://web.archive.org/web/20021120034302/http://online.securityfocus.com/bid/4229
  - url: >-
      https://web.archive.org/web/20070914020022/http://xforce.iss.net/xforce/xfdb/8334
  - url: 'http://marc.info/?l=bugtraq&m=101503023511996&w=2'
  - url: 'http://www.redhat.com/support/errata/RHSA-2002-060.html'
tags:
  - osv
  - pip
epss: 0.01584
epssPercentile: 0.74072
ingestedAt: '2026-07-08T18:25:48.307Z'
---

## Overview

Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violation of the intended configuration.

## Affected packages

- `zope >= 2.2.0, < 2.4.4`
- `zope >= 2.5.0, < 2.5.1`

## Remediation

Upgrade to a patched release:

- `zope 2.4.4`
- `zope 2.5.1`
