CVE-2022-26661
Summary
| CVE | CVE-2022-26661 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-10 17:47:00 UTC |
| Updated | 2022-03-18 14:46:00 UTC |
| Description | An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An authenticated user can make the server parse a crafted XML SEPA file to access arbitrary files on the system. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2946-1] tryton-proteus security update |
MLIST |
lists.debian.org |
|
| [SECURITY] [DLA 2945-1] tryton-server security update |
MLIST |
lists.debian.org |
|
| Debian -- Security Information -- DSA-5098-1 tryton-server |
DEBIAN |
www.debian.org |
|
| Security Release for issue11219 and issue11244 - News - Tryton Discussion |
MISC |
discuss.tryton.org |
|
| Debian -- Security Information -- DSA-5099-1 tryton-proteus |
DEBIAN |
www.debian.org |
|
| Issue 11219: A user can read the content of files on the machine running trytond by exploiting XEE vulnerability in camt54 parsing - Tryton issue tracker |
MISC |
bugs.tryton.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179124 Debian Security Update for tryton-server (DLA 2945-1)
- 179125 Debian Security Update for tryton-proteus (DLA 2946-1)
- 179141 Debian Security Update for tryton-server (DSA 5098-1)
- 179147 Debian Security Update for tryton-proteus (DSA 5099-1)
- 181965 Debian Security Update for tryton-servertryton-proteus (CVE-2022-26661)