-
Notifications
You must be signed in to change notification settings - Fork 109
Expand file tree
/
Copy pathPYSEC-2022-43170.yaml
More file actions
68 lines (68 loc) · 1.81 KB
/
Copy pathPYSEC-2022-43170.yaml
File metadata and controls
68 lines (68 loc) · 1.81 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
id: PYSEC-2022-43170
modified: 2024-11-21T14:23:02.248212Z
published: 2022-03-10T17:47:00Z
aliases:
- CVE-2022-26661
details: An XXE issue was discovered in Tryton Application Platform (Server) 5.x through
5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application
Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4,
and 6.1.x and 6.2.x through 6.2.1. An authenticated user can make the server parse
a crafted XML SEPA file to access arbitrary files on the system.
affected:
- package:
ecosystem: PyPI
name: tryton
purl: pkg:pypi/tryton
ranges:
- type: ECOSYSTEM
events:
- introduced: 5.0.0
- fixed: 5.0.12
- introduced: 6.0.0
- fixed: 6.0.5
- introduced: 6.2.0
- fixed: 6.2.2
versions:
- 5.0.0
- 5.0.1
- 5.0.10
- 5.0.11
- 5.0.2
- 5.0.3
- 5.0.4
- 5.0.5
- 5.0.6
- 5.0.7
- 5.0.8
- 5.0.9
- 6.0.0
- 6.0.1
- 6.0.2
- 6.0.3
- 6.0.4
- 6.2.0
- 6.2.1
severity:
- type: CVSS_V3
score: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
references:
- type: EVIDENCE
url: https://bugs.tryton.org/issue11219
- type: REPORT
url: https://bugs.tryton.org/issue11219
- type: ADVISORY
url: https://bugs.tryton.org/issue11219
- type: ADVISORY
url: https://discuss.tryton.org/t/security-release-for-issue11219-and-issue11244/5059
- type: ARTICLE
url: https://lists.debian.org/debian-lts-announce/2022/03/msg00016.html
- type: WEB
url: https://lists.debian.org/debian-lts-announce/2022/03/msg00016.html
- type: ARTICLE
url: https://lists.debian.org/debian-lts-announce/2022/03/msg00017.html
- type: WEB
url: https://lists.debian.org/debian-lts-announce/2022/03/msg00017.html
- type: ADVISORY
url: https://www.debian.org/security/2022/dsa-5098
- type: ADVISORY
url: https://www.debian.org/security/2022/dsa-5099