CVE-2019-10868: Medium severity tryton vulnerability
In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the user to guess values.
Other sources
In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the user to guess values.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-10868?
CVE-2019-10868 is a vulnerability that allows an authenticated user to order records based on a field for which they have no access right.
What is the severity of CVE-2019-10868?
The severity of CVE-2019-10868 is medium, with a CVSS score of 6.5.
How does CVE-2019-10868 impact Tryton?
CVE-2019-10868 impacts Tryton versions 4.2, 4.4, 4.6, 4.8, and 5.0.
What is the remedy for CVE-2019-10868?
To remedy CVE-2019-10868, users should upgrade to Tryton version 5.0.6 for pip installations or the corresponding remedial versions for Debian installations.
Where can I find more information about CVE-2019-10868?
More information about CVE-2019-10868 can be found at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-10868), [Tryton Security Release](https://discuss.tryton.org/t/security-release-for-issue8189/1262), [GitHub Advisory](https://github.com/advisories/GHSA-f6f2-pwrj-64h3).