CVE Vulnerabilities

CVE-2015-0861

Published: Apr 13, 2016 | Modified: Feb 01, 2019
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.

Affected Software

Name Vendor Start Version End Version
Trytond Tryton 3.2.0 (including) 3.2.10 (excluding)
Trytond Tryton 3.4.0 (including) 3.4.8 (excluding)
Trytond Tryton 3.6.0 (including) 3.6.5 (excluding)
Trytond Tryton 3.8.0 (including) 3.8.1 (excluding)
Tryton-server Ubuntu artful *
Tryton-server Ubuntu precise *
Tryton-server Ubuntu upstream *
Tryton-server Ubuntu vivid *
Tryton-server Ubuntu wily *
Tryton-server Ubuntu yakkety *
Tryton-server Ubuntu zesty *

References