CVE-2019-10868
MEDIUM EPSS 66.3%
Published Apr 5, 20197y ago · Modified Jun 17, 20262w ago
6.5 CVSS 3.1
Published Apr 5, 2019 7y ago
Last Modified Jun 17, 2026 2w ago
Description
In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the user to guess values.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability None
Threat Intelligence
EPSS Exploit Probability
66.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-862 Missing Authorization Authorization
Affected Products 6
References 4
- discuss.tryton.org https://discuss.tryton.org/t/security-release-for-issue8189/1262
- hg.tryton.org https://hg.tryton.org/trytond/rev/f58bbfe0aefb
- seclists.org https://seclists.org/bugtraq/2019/Apr/14
- debian.org https://www.debian.org/security/2019/dsa-4426
Remediation
- hg.tryton.org https://hg.tryton.org/trytond/rev/f58bbfe0aefb