CVE-2018-19443
Summary
| CVE | CVE-2018-19443 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-11-22 19:29:00 UTC |
| Updated | 2018-12-20 01:25:00 UTC |
| Description | The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in bus.py and jsonrpc.py. This connection attempt fails, but it contains in the header the current session of the user. This session could then be stolen by a man-in-the-middle. |
Risk And Classification
Problem Types: CWE-384
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Release for issue7792 - News - Tryton Discussion | MISC | discuss.tryton.org | Vendor Advisory |
| Issue 7792: Bus fails on ssl connection - Tryton issue tracker | MISC | bugs.tryton.org | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981398 Python (pip) Security Update for tryton (GHSA-32w7-9whp-cjp9)