QID 982303
QID 982303: Python (pip) Security Update for tryton (GHSA-f6f2-pwrj-64h3)
In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the user to guess values.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-f6f2-pwrj-64h3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-f6f2-pwrj-64h3 -
github.com/advisories/GHSA-f6f2-pwrj-64h3
CVEs related to QID 982303
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-f6f2-pwrj-64h3 | tryton |
|