CVE-2022-26662
Summary
| CVE | CVE-2022-26662 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-10 17:47:00 UTC |
| Updated | 2022-03-18 15:07:00 UTC |
| Description | An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An unauthenticated user can send a crafted XML-RPC message to consume all the resources of the server. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2946-1] tryton-proteus security update |
MLIST |
lists.debian.org |
|
| [SECURITY] [DLA 2945-1] tryton-server security update |
MLIST |
lists.debian.org |
|
| Debian -- Security Information -- DSA-5098-1 tryton-server |
DEBIAN |
www.debian.org |
|
| Security Release for issue11219 and issue11244 - News - Tryton Discussion |
MISC |
discuss.tryton.org |
|
| Issue 11244: A non authenticated user can cause a denial of service with a single request using an xml bomb attack on xmlrpc - Tryton issue tracker |
MISC |
bugs.tryton.org |
|
| Debian -- Security Information -- DSA-5099-1 tryton-proteus |
DEBIAN |
www.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179124 Debian Security Update for tryton-server (DLA 2945-1)
- 179125 Debian Security Update for tryton-proteus (DLA 2946-1)
- 179141 Debian Security Update for tryton-server (DSA 5098-1)
- 179147 Debian Security Update for tryton-proteus (DSA 5099-1)
- 183136 Debian Security Update for tryton-servertryton-proteus (CVE-2022-26662)