CVE-2012-0215 Information

Description

model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create (2) write (3) delete or (4) copy rpc call.

Reference

http://hg.tryton.org/trytond/rev/8e64d52ecea4 http://news.tryton.org/2012/03/security-releases-for-all-supported.html http://www.debian.org/security/2012/dsa-2444 https://bugs.tryton.org/issue2476

Share on: