GHSA-jpr7-8rxm-4vgx
Dashboard / Vulnerabilities / GHSA-jpr7-8rxm-4vgx
GHSA-jpr7-8rxm-4vgx
Summary: Tryton allow authenticated users with certain permissions to read arbitrary files via the name parameter
Details: `file_open` in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with certain permissions to read arbitrary files via the name parameter or unspecified other vectors.
References: https://nvd.nist.gov/vuln/detail/CVE-2016-1242, https://bugs.tryton.org/issue5808, https://github.com/pypa/advisory-database/tree/main/vulns/tryton/PYSEC-2016-41.yaml, https://github.com/pypa/advisory-database/tree/main/vulns/trytond/PYSEC-2016-13.yaml, https://github.com/tryton/trytond, http://www.debian.org/security/2016/dsa-3656, http://www.tryton.org/posts/security-release-for-issue5795-and-issue5808.html
Affected packages
Package
Name: trytond
Purl: pkg:pypi/trytond
Affected ranges
Type: ECOSYSTEM
Events:
