CVE-2012-0215
Publication date 12 July 2012
Last updated 24 July 2024
Ubuntu priority
Description
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| tryton-server | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |