Description
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2444-1 | tryton-server security update |
EUVD |
EUVD-2012-0030 | model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call. |
Github GHSA |
GHSA-cqg4-rf29-3mv6 | Trytond allows modification of privileges of arbitrary users |
References
History
No history.
Status: PUBLISHED
Assigner: debian
Published:
Updated: 2024-09-16T16:53:53.880Z
Reserved: 2011-12-14T00:00:00.000Z
Link: CVE-2012-0215
No data.
Status : Modified
Published: 2012-07-12T20:55:09.857
Modified: 2026-04-29T01:13:23.040
Link: CVE-2012-0215
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Github GHSA