CVE-2022-26661: XEE
An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An authenticated user can make the server parse a crafted XML SEPA file to access arbitrary files on the system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this XXE issue?
The vulnerability ID for this XXE issue is CVE-2022-26661.
What is the severity of CVE-2022-26661?
The severity of CVE-2022-26661 is medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2022-26661?
The affected versions of Tryton Application Platform (Server) are 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5. The affected versions of Tryton Application Platform (Command Line Client (proteus)) are 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1.
How can I fix CVE-2022-26661?
To fix CVE-2022-26661, update Tryton Application Platform (Server) to version 5.0.46 or above, 6.0.16 or above, or 6.2.6 or above. Update Tryton Application Platform (Command Line Client (proteus)) to version 5.0.12 or above, 6.0.5 or above, or 6.2.2 or above.
Where can I find more information about CVE-2022-26661?
You can find more information about CVE-2022-26661 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-26661), [Tryton Discussion](https://discuss.tryton.org/t/security-release-for-issue11219-and-issue11244/5059), [Debian LTS Announcement](https://lists.debian.org/debian-lts-announce/2022/03/msg00016.html).