CVE-2012-0215
Summary
| CVE | CVE-2012-0215 |
|---|---|
| State | PUBLISHED |
| Assigner | debian |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-07-12 20:55:09 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Issue 2476: Missing access control on some relation model for Many2Many - Tryton issue tracker | af854a3a-2127-422b-91ae-364da2661108 | bugs.tryton.org | |
| Tryton: Security Releases for all supported series | af854a3a-2127-422b-91ae-364da2661108 | news.tryton.org | Vendor Advisory |
| Debian -- Security Information -- DSA-2444-1 tryton-server | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| trytond: 8e64d52ecea4 | af854a3a-2127-422b-91ae-364da2661108 | hg.tryton.org | Exploit, Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 996734 Python (Pip) Security Update for trytond (GHSA-cqg4-rf29-3mv6)