Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqg4-rf29-3mv6

Опубликовано: 04 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Trytond allows modification of privileges of arbitrary users

model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.

Пакеты

Наименование

trytond

pip
Затронутые версииВерсия исправления

< 2.4.0

2.4.0

EPSS

Процентиль: 69%
0.00617
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 13 лет назад

model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.

nvd
больше 13 лет назад

model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.

debian
больше 13 лет назад

model/modelstorage.py in the Tryton application framework (trytond) be ...

EPSS

Процентиль: 69%
0.00617
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-287