Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
Any version before 6.0.70
affected
7.0.0 (semver) before 7.0.40
affected
7.1.0 (semver) before 7.4.21
affected
7.5.0 (semver) before 7.6.11
affected
Description
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
Problem types
CWE-402 Transmission of Private Resources into a New Sphere ('Resource Leak')
Product status
Any version before 6.0.70
7.0.0 (semver) before 7.0.40
7.1.0 (semver) before 7.4.21
7.5.0 (semver) before 7.6.11
References
discuss.tryton.org/t/security-release-for-issue-14354/8950
foss.heptapod.net/tryton/tryton/-/issues/14354