Candidate: CVE-2015-0861 PublicDate: 2016-04-13 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0861 Description: model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records. Ubuntu-Description: Notes: debian> Mathias Behrle told us that affected versions are >= 3.2 and < 3.8.1 Bugs: https://bugs.tryton.org/issue5167 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N [4.3 MEDIUM] Patches_tryton-server: upstream: https://codereview.tryton.org/22631002 upstream_tryton-server: released (3.8.1-1) precise_tryton-server: ignored (reached end-of-life) precise/esm_tryton-server: DNE (precise was needed) trusty_tryton-server: not-affected (code not present) trusty/esm_tryton-server: DNE (trusty was not-affected [code not present]) vivid_tryton-server: released (3.4.0-3+deb8u1build0.15.04.1) vivid/stable-phone-overlay_tryton-server: DNE vivid/ubuntu-core_tryton-server: DNE wily_tryton-server: ignored (reached end-of-life) xenial_tryton-server: not-affected (3.8.1-1) yakkety_tryton-server: ignored (reached end-of-life) zesty_tryton-server: ignored (reached end-of-life) artful_tryton-server: ignored (reached end-of-life) bionic_tryton-server: not-affected (3.8.1-1) devel_tryton-server: not-affected (3.8.1-1)