CVE-2012-0215
Publication date 12 July 2012
Last updated 24 July 2024
Ubuntu priority
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.
Status
Package | Ubuntu Release | Status |
---|---|---|
tryton-server | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |