QID 996734
Date Published: 2024-01-17
QID 996734: Python (Pip) Security Update for trytond (GHSA-cqg4-rf29-3mv6)
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-cqg4-rf29-3mv6 for updates and patch information.
Vendor References
- GHSA-cqg4-rf29-3mv6 -
github.com/advisories/GHSA-cqg4-rf29-3mv6
CVEs related to QID 996734
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cqg4-rf29-3mv6 | trytond |
|