CVE Vulnerabilities

CVE-2015-0861

Published: Apr 13, 2016 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.

Affected Software

Name Vendor Start Version End Version
Trytond Tryton 3.2.0 (including) 3.2.10 (excluding)
Trytond Tryton 3.4.0 (including) 3.4.8 (excluding)
Trytond Tryton 3.6.0 (including) 3.6.5 (excluding)
Trytond Tryton 3.8.0 (including) 3.8.1 (excluding)
Tryton-server Ubuntu artful *
Tryton-server Ubuntu precise *
Tryton-server Ubuntu upstream *
Tryton-server Ubuntu vivid *
Tryton-server Ubuntu wily *
Tryton-server Ubuntu yakkety *
Tryton-server Ubuntu zesty *

References