Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pm3h-mm62-pwm8

Опубликовано: 11 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

XML Entity Expansion in trytond and proteus

An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An unauthenticated user can send a crafted XML-RPC message to consume all the resources of the server.

Пакеты

Наименование

trytond

pip
Затронутые версииВерсия исправления

>= 5.0.0, < 5.0.46

5.0.46

Наименование

trytond

pip
Затронутые версииВерсия исправления

>= 6.0.0, < 6.0.16

6.0.16

Наименование

trytond

pip
Затронутые версииВерсия исправления

>= 6.1.0, < 6.2.6

6.2.6

Наименование

proteus

pip
Затронутые версииВерсия исправления

>= 5.0.0, < 5.0.12

5.0.12

Наименование

proteus

pip
Затронутые версииВерсия исправления

>= 6.0.0, < 6.0.5

6.0.5

Наименование

proteus

pip
Затронутые версииВерсия исправления

>= 6.1.0, < 6.2.2

6.2.2

EPSS

Процентиль: 90%
0.05585
Низкий

7.5 High

CVSS3

Дефекты

CWE-776

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An unauthenticated user can send a crafted XML-RPC message to consume all the resources of the server.

CVSS3: 7.5
nvd
почти 4 года назад

An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An unauthenticated user can send a crafted XML-RPC message to consume all the resources of the server.

CVSS3: 7.5
debian
почти 4 года назад

An XML Entity Expansion (XEE) issue was discovered in Tryton Applicati ...

EPSS

Процентиль: 90%
0.05585
Низкий

7.5 High

CVSS3

Дефекты

CWE-776