CVE-2012-2238: High severity tryton trytond vulnerability
trytond 2.4: ModelView.button fails to validate authorization.
Other sources
trytond 2.4: ModelView.button fails to validate authorization
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2012-2238?
CVE-2012-2238 is a vulnerability in trytond 2.4 where ModelView.button fails to validate authorization.
How severe is CVE-2012-2238?
CVE-2012-2238 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2012-2238?
The affected software versions are: tryton-server 5.0.4-2+deb10u1, tryton-server 5.0.4-2+deb10u2, tryton-server 5.0.33-2+deb11u2, tryton-server 6.0.29-2+deb12u1, and tryton-server 6.0.36-1.
How can I fix CVE-2012-2238?
To fix CVE-2012-2238, update your tryton-server to version 5.0.4-2+deb10u1, 5.0.4-2+deb10u2, 5.0.33-2+deb11u2, 6.0.29-2+deb12u1, or 6.0.36-1.
Where can I find more information about CVE-2012-2238?
More information about CVE-2012-2238 can be found at the following references: https://security-tracker.debian.org/tracker/CVE-2012-2238, http://hg.tryton.org/2.4/trytond/rev/279f0031b461, http://www.openwall.com/lists/oss-security/2012/09/11/10