CVE-2019-10868

MEDIUM EPSS 66.3%
Published Apr 5, 20197y ago · Modified Jun 17, 20262w ago
6.5 CVSS 3.1
Medium
Find Similar
Published Apr 5, 2019 7y ago
Last Modified Jun 17, 2026 2w ago

Description

In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the user to guess values.

CVSS Details

Base Score
6.5
Exploitability
2.8
Impact
3.6
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability None

Threat Intelligence

EPSS Exploit Probability
66.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-862 Missing Authorization Authorization

Affected Products 6

VendorProductVersionRange
trytontrytond*≥4.2.0  –  <4.2.21
trytontrytond*≥4.4.0  –  <4.4.19
trytontrytond*≥4.6.0  –  <4.6.14
trytontrytond*≥4.8.0  –  <4.8.10
trytontrytond*≥5.0.0  –  <5.0.6
debiandebian_linux9.0any

References 4

  • discuss.tryton.org https://discuss.tryton.org/t/security-release-for-issue8189/1262
    Vendor Advisory
  • hg.tryton.org https://hg.tryton.org/trytond/rev/f58bbfe0aefb
    PatchVendor Advisory
  • seclists.org https://seclists.org/bugtraq/2019/Apr/14
    Mailing ListThird Party Advisory
  • debian.org https://www.debian.org/security/2019/dsa-4426
    Third Party Advisory

Remediation

  • hg.tryton.org https://hg.tryton.org/trytond/rev/f58bbfe0aefb
    PatchVendor Advisory