Описание
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2.2.3-1 |
| esm-apps/xenial | not-affected | 2.2.3-1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [2.2.3-1]] |
| hardy | DNE | |
| lucid | ignored | end of life |
| maverick | ignored | end of life |
| natty | released | 1.6.1-2+squeeze1build0.11.04.1 |
| oneiric | ignored | end of life |
| precise | ignored | end of life |
| precise/esm | DNE | precise was needed |
Показывать по
EPSS
5.5 Medium
CVSS2
Связанные уязвимости
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.
model/modelstorage.py in the Tryton application framework (trytond) be ...
Trytond allows modification of privileges of arbitrary users
EPSS
5.5 Medium
CVSS2