CVE-2022-26662: XEE
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An unauthenticated user can send a crafted XML-RPC message to consume all the resources of the server.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-26662?
CVE-2022-26662 is an XML Entity Expansion (XEE) issue discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.
What is the severity of CVE-2022-26662?
CVE-2022-26662 has a severity keyword of 'high' and a severity value of 7.5.
How does CVE-2022-26662 affect Tryton Application Platform (Server)?
CVE-2022-26662 affects Tryton Application Platform (Server) versions 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5.
How does CVE-2022-26662 affect Tryton Application Platform (Command Line Client - proteus)?
CVE-2022-26662 affects Tryton Application Platform (Command Line Client - proteus) versions 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.
Are there any references related to CVE-2022-26662?
Yes, there are references related to CVE-2022-26662. You can find them here: [1]https://bugs.tryton.org/issue11244, [2]https://discuss.tryton.org/t/security-release-for-issue11219-and-issue11244/5059, [3]https://lists.debian.org/debian-lts-announce/2022/03/msg00016.html.