MEDIUM · 5.5

CVE-2012-0215

model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenti...

Vulnerability Description

model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.

CVSS Score

5.5

MEDIUM

AV:N/AC:L/Au:S/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
TrytonTrytond<= 2.2.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-0215?

CVE-2012-0215 is a vulnerability with a CVSS score of 5.5 (MEDIUM). model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenti...

How severe is CVE-2012-0215?

CVE-2012-0215 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-0215?

Check the references section above for vendor advisories and patch information. Affected products include: Tryton Trytond.