CVE-2012-0215
published 2012-07-12CVE-2012-0215: model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the…
PriorityP429medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
1.97%
78.3th percentile
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tryton-server | < tryton-server 2.2.2-1 (bookworm) | tryton-server 2.2.2-1 (bookworm) |
| tryton | trytond | <= 2.2.3 | — |
| tryton | trytond | — | — |
| tryton | trytond | — | — |
| tryton | trytond | — | — |
| tryton | trytond | — | — |
| tryton | trytond | >= 0 < 2.4.0 | 2.4.0 |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Trytond allows modification of privileges of arbitrary users
ghsa·2022-05-04
CVE-2012-0215 [HIGH] CWE-287 Trytond allows modification of privileges of arbitrary users
Trytond allows modification of privileges of arbitrary users
`model/modelstorage.py` in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.
OSV
Trytond allows modification of privileges of arbitrary users
osv·2022-05-04
CVE-2012-0215 [HIGH] Trytond allows modification of privileges of arbitrary users
Trytond allows modification of privileges of arbitrary users
`model/modelstorage.py` in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.
OSV
CVE-2012-0215: model/modelstorage
osv·2012-07-12·CVSS 5.5
CVE-2012-0215 [MEDIUM] CVE-2012-0215: model/modelstorage
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.
Debian
CVE-2012-0215: tryton-server - model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0...
vendor_debian·2012·CVSS 5.5
CVE-2012-0215 [MEDIUM] CVE-2012-0215: tryton-server - model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0...
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.
Scope: local
bookworm: resolved (fixed in 2.2.2-1)
bullseye: resolved (fixed in 2.2.2-1)
forky: resolved (fixed in 2.2.2-1)
sid: resolved (fixed in 2.2.2-1)
trixie: resolved (fixed in 2.2.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://hg.tryton.org/trytond/rev/8e64d52ecea4http://news.tryton.org/2012/03/security-releases-for-all-supported.htmlhttp://www.debian.org/security/2012/dsa-2444https://bugs.tryton.org/issue2476http://hg.tryton.org/trytond/rev/8e64d52ecea4http://news.tryton.org/2012/03/security-releases-for-all-supported.htmlhttp://www.debian.org/security/2012/dsa-2444https://bugs.tryton.org/issue2476
2012-07-12
Published