Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-10868

Опубликовано: 05 апр. 2019
Источник: ubuntu
Приоритет: medium
CVSS2: 4
CVSS3: 6.5

Описание

In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the user to guess values.

РелизСтатусПримечание
bionic

not-affected

code not present
cosmic

not-affected

code not present
devel

not-affected

6.0.19-1
disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

not-affected

code not present
esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

not-affected

6.0.19-1
esm-apps/xenial

not-affected

code not present

Показывать по

4 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 7 лет назад

In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the user to guess values.

CVSS3: 6.5
debian
почти 7 лет назад

In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 befo ...

CVSS3: 6.5
github
почти 7 лет назад

Tryton Improper Access Control

CVSS3: 6.5
fstec
почти 7 лет назад

Уязвимость компонента modelstorage.py платформы для разработки приложений Tryton, связанная с неправильным контролем доступа, позволяющая нарушителю раскрыть защищаемую информацию

4 Medium

CVSS2

6.5 Medium

CVSS3