Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-26661

Опубликовано: 10 мар. 2022
Источник: debian
EPSS Низкий

Описание

An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An authenticated user can make the server parse a crafted XML SEPA file to access arbitrary files on the system.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tryton-proteusfixed6.0.5-1package
tryton-serverfixed6.0.16-1package

Примечания

  • https://bugs.tryton.org/issue11219

  • https://discuss.tryton.org/t/security-release-for-issue11219-and-issue11244/5059

EPSS

Процентиль: 65%
0.00484
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 4 года назад

An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An authenticated user can make the server parse a crafted XML SEPA file to access arbitrary files on the system.

CVSS3: 6.5
nvd
почти 4 года назад

An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An authenticated user can make the server parse a crafted XML SEPA file to access arbitrary files on the system.

CVSS3: 6.5
github
почти 4 года назад

Improper Restriction of XML External Entity Reference in trytond and proteus

EPSS

Процентиль: 65%
0.00484
Низкий