CVE-2018-19443: Medium severity tryton vulnerability

Published Nov 22, 2018
·
Updated

The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in bus.py and jsonrpc.py. This connection attempt fails, but it contains in the header the current session of the user. This session could then be stolen by a man-in-the-middle.

Affected Software

2 affected componentsFixes available
pip/tryton=5.0.0
5.0.1
tryton Tryton=5.0.0

Event History

Nov 22, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Nov 29, 2018
Advisory Published
via GitHub·09:30 PM

Frequently Asked Questions

1

What is CVE-2018-19443?

CVE-2018-19443 is a vulnerability in Tryton 5.x before version 5.0.1 that allows an attacker to steal the session of a user.

2

How does CVE-2018-19443 affect Tryton?

CVE-2018-19443 affects Tryton version 5.0.0, allowing the client to make a cleartext connection to the bus instead of an encrypted connection.

3

How severe is CVE-2018-19443?

CVE-2018-19443 has a severity level of medium with a CVSS score of 5.9.

4

How can I fix CVE-2018-19443?

To fix CVE-2018-19443, upgrade Tryton to version 5.0.1 or later.

5

Where can I find more information about CVE-2018-19443?

More information about CVE-2018-19443 can be found at the following references: [1] [2]

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203